{"id":7525,"date":"2025-10-10T01:05:45","date_gmt":"2025-10-10T01:05:45","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=7525"},"modified":"2025-10-10T01:05:46","modified_gmt":"2025-10-10T01:05:46","slug":"sonicwall-says-hackers-breached-all-of-its-firewall-backups","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=7525","title":{"rendered":"SonicWall Says Hackers Breached All of Its Firewall Backups"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>In September 2025, SonicWall reported an information breach of its cloud backup service, stating that fewer than 5% of its prospects have been affected. On the time, the problem appeared contained and below investigation. That modified at the moment after SonicWall and incident response agency Mandiant confirmed that the attackers had accessed backup configuration recordsdata for each buyer utilizing the service.<\/p>\n<p>The breach started with a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/brute-force-campaign-fortinet-ssl-vpn-coordinated-attack\/\" data-type=\"post\" data-id=\"133386\" target=\"_blank\" rel=\"noreferrer noopener\">brute power assault<\/a> focusing on the MySonicWall cloud backup API, which shops encrypted firewall configuration recordsdata. These recordsdata embrace detailed community guidelines, credentials and routing knowledge used to revive or replicate SonicWall firewalls. Whereas the passwords and keys stay encrypted, the attackers now maintain full configuration knowledge that may very well be worthwhile for mapping or exploiting buyer networks.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p style=\"font-style:normal;font-weight:300\"><em>\u201cThe investigation confirmed that an unauthorised celebration accessed firewall configuration backup recordsdata for all prospects who&#8217;ve used SonicWall\u2019s cloud backup service. The recordsdata comprise encrypted credentials and configuration knowledge; whereas encryption stays in place, possession of those recordsdata might enhance the danger of focused assaults.\u201d<\/em><\/p>\n<p><cite>SonicWall<\/cite><\/p><\/blockquote>\n<p>SonicWall\u2019s ultimate investigation <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/mysonicwall-cloud-backup-file-incident\/250915160910330\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a> says up to date lists of affected gadgets at the moment are accessible within the MySonicWall portal. Prospects can see whether or not their firewalls are labelled \u201cEnergetic \u2013 Excessive Precedence,\u201d \u201cEnergetic \u2013 Decrease Precedence,\u201d or \u201cInactive,\u201d relying on publicity stage. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2.png\"><img loading=\"lazy\" decoding=\"async\" width=\"911\" height=\"505\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2.png\" alt=\"SonicWall Says All Firewall Backups Were Accessed by Hackers\" class=\"wp-image-135839\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2.png 911w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2-300x166.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2-768x426.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2-380x211.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/10\/sonicwall-hackers-breached-all-firewall-backups-2-800x443.png 800w\" sizes=\"auto, (max-width: 911px) 100vw, 911px\"\/><\/a><\/figure>\n<\/div>\n<p>The corporate has additionally added new monitoring instruments, strengthened its cloud infrastructure, and printed detailed remediation steerage. Prospects are suggested to focus first on high-priority gadgets with internet-facing companies, utilizing the help instrument offered to determine which configurations want quick overview.<\/p>\n<p>SonicWall says it continues to work with Mandiant to strengthen its methods and help affected prospects. The corporate\u2019s up to date communication emphasises transparency and prevention after what has change into one in every of its most in depth safety incidents thus far.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/ryandewhurst\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ryan Dewhurst<\/a>, Head of Proactive Menace Intelligence at watchTowr, mentioned the breach is severe due to the kind of knowledge uncovered. \u201cAttackers gained entry to a treasure trove of delicate data, together with firewall guidelines and encrypted credentials,\u201d he mentioned. \u201cRegardless that passwords are encrypted, in the event that they have been weak, they are often cracked offline. And even with out that, the configuration knowledge offers attackers sufficient perception to plan extra focused assaults.\u201d<\/p>\n<p>He additionally questioned why a service internet hosting such delicate knowledge lacked fundamental protecting measures. \u201cA brute power assault on an API ought to have been blocked by charge limiting and stronger entry controls,\u201d Dewhurst famous.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="eNoqyMnOYAm4GhakoCzD"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In September 2025, SonicWall reported an information breach of its cloud backup service, stating that fewer than 5% of its prospects have been affected. On the time, the problem appeared contained and below investigation. That modified at the moment after SonicWall and incident response agency Mandiant confirmed that the attackers had accessed backup configuration recordsdata [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":7527,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2834,5098,626,554,2037],"class_list":["post-7525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-backups","tag-breached","tag-firewall","tag-hackers","tag-sonicwall"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7525"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7525\/revisions"}],"predecessor-version":[{"id":7526,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7525\/revisions\/7526"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/7527"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 04:26:51 UTC -->