Cyberscoop
SonicWall Credential Stuffing Campaign Compromises 30 Organizations in 2 Days
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Starting July 25, 2026, Huntress detected a credential stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations in under two days. The attackers validated credentials against remote access portals, resulting in 92 unique user accounts being compromised. The attack was broad and opportunistic, affecting various SonicWall devices without specific targeting. Huntress noted that the attackers refrained from post-compromise activity, suggesting potential pre-positioning for future attacks. SonicWall has not yet released a security advisory regarding this incident. The campaign's abrupt end indicates a possible rotation of infrastructure by the attackers. Huntress is actively monitoring the situation and providing remediation guidance to affected partners.
Key Points: • Credential stuffing campaign compromised 30 organizations in 41 hours. • Attackers validated credentials against SonicWall VPN and firewall accounts. • No post-compromise activity observed, indicating potential future attacks.