SonicWall has officially confirmed that a state-sponsored hacking group was responsible for the September 2025 cyber-intrusion that led to the unauthorized exposure of firewall configuration backup files stored in its cloud infrastructure.
According to the company’s disclosure this week, the breach stemmed from the unauthorized access of cloud backup files via a specific API call. The malicious activity was confined to a single cloud environment and did not affect SonicWall’s firmware, products, or broader systems. The company emphasized that this incident is unrelated to the ongoing Akira ransomware campaigns targeting other network devices worldwide.
When SonicWall first reported the breach in September, it estimated that less than 5% of customers who used its cloud backup service were impacted. However, the latest update confirms that all backup configuration data accessed belonged to customers using MySonicWall’s Cloud Backup feature, highlighting the potential exposure of sensitive firewall metadata such as network rules, VPN settings, and encrypted credentials.
To ensure transparency and reinforce trust, SonicWall engaged Google-owned Mandiant to conduct a forensic investigation. Following Mandiant’s recommendations, the company has implemented comprehensive network-hardening and cloud-security measures to strengthen its infrastructure.
SonicWall noted that nation-state-backed groups increasingly target edge-security vendors, especially those safeguarding SMB and distributed environments. In response, it reiterated its commitment to bolstering security resilience for partners and customers at the frontline of these escalating threats.
The company has introduced two essential tools for remediation:
-
An Online Analysis Tool to help customers identify affected devices or services.
-
A Credentials Reset Tool for secure password rotation and reconfiguration.
SonicWall customers are urged to log in to MySonicWall.com, verify their devices, and reset credentials for any impacted services immediately.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.



