SonicWall confirms all cloud backup users impacted in September data breach

SonicWall has confirmed that all customers using its cloud backup service to store firewall configuration files were affected by a recent data breach.

The breach, which occurred in early September and was initially reported weeks later, was originally believed to have impacted less than 5% of customers. However, a new update on October 8 revealed that threat actors accessed configuration files for all firewalls backed up to the MySonicWall cloud service.

“The files contain encrypted credentials and configuration data; while encryption remains in place, possession of these files could increase the risk of targeted attacks,” the company has warned in an advisory.

The vendor is actively notifying affected customers and partners, and has released assessment and remediation tools. A list of impacted devices is now available in the MySonicWall portal under Product Management > Issue List.

SonicWall is urging all users to log into their MySonicWall accounts to verify if their devices are at risk. Customers should also reset all passwords and follow the company's containment and mitigation guidelines.

Back to the list

Latest Posts

Thousands of domains target hotel guests in massive phishing campaign

The campaign employs a phishing kit that customizes the page presented to the site visitor depending on a unique string in the URL path.
12 November 2025

Hackers exploit Citrix and Cisco zero-days to deploy custom malware

Attackers leveraged the Cisco flaw to gain pre-authentication admin access and installed a custom web shell called “IdentityAuditAction,” masquerading as a legitimate ISE component.
12 November 2025

Russian hacker to plead guilty for role in Yanluowang ransomware attacks

Volkov acted as an initial access broker for the Yanluowang ransomware group breaking into company networks and selling access to other hackers.
12 November 2025