What Huntress found
Managed detection and response firm Huntress published a threat advisory on July 29, 2026 detailing a credential stuffing campaign against SonicWall VPN and firewall devices. The activity began on a Saturday and continued for roughly 41 hours before stopping abruptly on Monday, during which attackers successfully authenticated to 92 unique user accounts spread across 30 different customer organizations. Huntress released the advisory the following Tuesday after confirming the pattern across its managed customer base. The 30 affected organizations span a range of industries and sizes, according to Huntress, indicating an opportunistic sweep against any SonicWall device the attackers had valid credentials for rather than a campaign targeting a specific sector or company profile. Huntress said it is continuing to monitor for follow-on activity against the compromised accounts, including any attempts at lateral movement or data staging inside the affected networks.
Notably, this was not a vulnerability exploit. Every login used valid, legitimate credentials rather than a software flaw in SonicWall's firewall or VPN stack. That distinction matters operationally: there is no patch that fixes a credential stuffing campaign, because the software worked exactly as designed. The only real questions are where the credentials came from and how quickly compromised accounts get identified and locked down.
Where the credentials likely came from
Huntress laid out three plausible sources for the credential set attackers used, without pinning down which one applied in every case. The first is aggregation of infostealer malware logs, the commodity credential-harvesting malware that has become the dominant initial access vector across the ransomware ecosystem, feeding massive combolists traded on criminal marketplaces. The second is previously compromised SonicWall configuration files, which can contain stored credentials for VPN and administrative accounts if not properly secured or rotated after exposure.
The third possibility is residue from an earlier CVE-driven compromise, meaning credentials harvested during a past SonicWall vulnerability exploitation that yielded more usable accounts than the original attacker could act on at the time, later resold or reused by a different actor. Any of these sources point to the same underlying failure mode: credentials that should have been rotated after any prior exposure event were still valid months or years later.
The rapid start, rapid stop pattern
Michael Tigges, a Principal Tactical Response Analyst at Huntress, described the campaign's shape as a recognizable pattern rather than a one-off event. This fits campaign trends, he said. A rash of compromise will break out, followed by silence until the adversary rotates infrastructure. That framing matters for defenders because it means the absence of new detections after the weekend doesn't mean the threat has ended, only that the specific infrastructure used in this wave has likely been burned and will resurface elsewhere.
Tigges also flagged what happens after a successful login rather than just the login itself: with local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place. A compromised VPN account is rarely the end goal. It's the entry point attackers use to pivot laterally into internal systems, and organizations that treat VPN authentication as the only security boundary, without additional segmentation behind it, are exposed to exactly the kind of follow-on compromise Tigges is describing.
SonicWall's muted response
As of publication, SonicWall had not issued a formal security advisory acknowledging the campaign. A company spokesperson told reporters only that SonicWall was investigating and hoped to provide more information soon. That silence is notable given SonicWall's history: the vendor's firewall and VPN products have been repeatedly targeted by ransomware affiliates and nation-state actors over the past two years, and customers have grown increasingly wary of gaps between when SonicWall becomes aware of active exploitation and when it publishes actionable guidance. Several of the ransomware intrusions publicly tied to SonicWall devices in the past two years were later traced back to credential-based access rather than a fresh software exploit, which is the same pattern this campaign appears to follow. Customers who lived through those earlier incidents are likely to read this latest silence as a signal to act on their own rather than wait for official confirmation before rotating credentials.
Without vendor confirmation of scope or root cause, affected organizations are left largely to Huntress's independent telemetry to understand whether they were touched by this specific wave, which limits visibility for the many SonicWall customers who are not Huntress-monitored.
What SonicWall customers should do now
Rotate every credential associated with SonicWall VPN and remote access accounts immediately, regardless of whether your organization has seen any indication of compromise, given how unclear the credential source remains. Enforce multi-factor authentication on all remote access accounts if it is not already mandatory, since credential stuffing campaigns like this one are neutralized entirely by MFA that doesn't rely on SMS or push notifications alone. Where possible, restrict VPN authentication to known, allow-listed source IP ranges or require a managed device certificate in addition to a password, since either control alone would have stopped this specific campaign cold.
Just as importantly, review your network segmentation behind the VPN gateway. Tigges' warning about local network access being effectively unlimited without topology controls is the real risk here, not the initial login. Treat successful VPN authentication as a starting point for lateral movement monitoring, not a trust boundary, and audit remote access logs going back at least to late July for authentication patterns consistent with the compromise window Huntress identified.



