SonicWall confirmed that a security breach in September resulted in unauthorized access to firewall configuration backup files stored in certain MySonicWall accounts. The company, with support from Mandiant, determined that the attack was carried out by a state-sponsored threat actor and was limited to a specific cloud environment accessed via an API call. The breach did not impact SonicWall products, firmware, source code, or customer networks, but exposed sensitive information such as access credentials and tokens, prompting SonicWall to advise customers to reset passwords and shared secrets for various services and interfaces.
Following the incident, SonicWall notified all customers using its cloud backup service for firewall configurations and provided assessment tools to help identify affected devices. The company emphasized that the breach was unrelated to Akira ransomware or other ongoing attacks and has since implemented additional security measures based on Mandiant's recommendations. Law enforcement and external cybersecurity experts were engaged throughout the investigation, and SonicWall continues to strengthen its systems to prevent future incidents involving nation-state actors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
By early November 2025, SonicWall publicly said its September breach was carried out by a state-sponsored or nation-state threat actor. The company disclosed this attribution across statements cited by multiple security news outlets.
In September 2025, SonicWall experienced a security breach involving its customer portal and cloud backup environment, resulting in the theft of firewall backup data. Multiple later reports describe the incident as affecting customer backup information tied to SonicWall firewalls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcecyberscoop.com
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.