Hackers gained unauthorized access to firewall configuration backup files stored in SonicWall’s MySonicWall cloud backup service, impacting all users of the platform. The breach was initially disclosed in September 2025, when SonicWall urged customers to reset credentials after discovering that backup files tied to MySonicWall accounts had been exposed. Although SonicWall’s initial advisory suggested that under 5% of customers were affected, subsequent investigation confirmed that all customers using the cloud backup service were impacted. The stolen configuration files contain sensitive information, including encrypted credentials, user and group settings, DNS and log settings, and certificates, which could be leveraged by threat actors to compromise organizational networks. Only Gen 7 and newer SonicWall firewalls encrypt credentials and secrets in exported configuration files using AES-256, leaving older devices more vulnerable to exploitation. SonicWall has blocked further unauthorized access and is collaborating with cybersecurity experts and law enforcement to assess the full scope of the incident. The company has notified affected customers and provided detailed instructions for identifying impacted devices and remediating the risk. Customers are advised to import new preference files, a process that disrupts IPSec VPNs, TOTP bindings, and user access, requiring reconfiguration of VPN pre-shared keys and reset of TOTP and user passwords. To minimize operational impact, SonicWall recommends performing these actions during maintenance windows or periods of low activity, as the process necessitates an immediate firewall reboot. Arctic Wolf notes that threat actors, including nation-state and ransomware groups, have previously exploited exfiltrated firewall configuration files in subsequent attacks. SonicWall has established a dedicated support team to assist organizations with remediation and has published an in-depth advisory with up-to-date guidance. Organizations are strongly urged to reset credentials on all affected firewalls and to follow SonicWall’s recommendations to prevent unauthorized access. The exposure of these configuration files represents a significant risk, as they can provide attackers with the information needed to bypass network defenses. The incident underscores the importance of robust encryption for sensitive configuration data and the need for rapid response to cloud service breaches. SonicWall continues to work with partners and customers to ensure all affected systems are secured and to prevent further exploitation of the stolen data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following the broader impact disclosure, SonicWall warned customers to treat the incident as a security risk and to rotate passwords, keys, certificates, and other secrets associated with affected firewall configurations. The company also said it was working with Mandiant and implementing additional security measures and customer support tools.
After expanding its investigation, SonicWall revised its initial assessment and said the breach impacted 100% of customers using the cloud backup service, not a smaller subset previously believed. Reports said the exposed data included firewall configuration backup files and encrypted credentials that could aid follow-on attacks.
SonicWall announced it had investigated a security incident affecting MySonicWall firewall configuration backup files stored in its cloud backup service. The company said attackers had accessed customer backup data and began notifying affected users and publishing remediation guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcearcticwolf.com
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.