SonicWall Credential Stuffing Campaign Compromises 30 Organizations in 2 Days

SonicWall Credential Stuffing Campaign Compromises 30 Organizations in 2 Days

First seen 29 Jul 2026, 17:15 UTC HuntressCyberscoop 81% similarity 67.5

Article Content

Browse articles
ThreatCluster

Starting July 25, 2026, Huntress detected a credential stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations in under two days. The attackers validated credentials against remote access portals, resulting in 92 unique user accounts being compromised. The attack was broad and opportunistic, affecting various SonicWall devices without specific targeting. Huntress noted that the attackers refrained from post-compromise activity, suggesting potential pre-positioning for future attacks. SonicWall has not yet released a security advisory regarding this incident. The campaign's abrupt end indicates a possible rotation of infrastructure by the attackers. Huntress is actively monitoring the situation and providing remediation guidance to affected partners.

Key Points: • Credential stuffing campaign compromised 30 organizations in 41 hours. • Attackers validated credentials against SonicWall VPN and firewall accounts. • No post-compromise activity observed, indicating potential future attacks.

ThreatCluster AI How this analysis works

Timeline

2026-07-25
Credential stuffing campaign begins
Huntress detected a spike in successful logins to SonicWall devices, compromising 26 accounts across 6 organizations.
Huntress
2026-07-26
Attacks escalate
The campaign grew, compromising 34 unique user accounts across 16 organizations within a day.
Huntress
2026-07-27
Further compromises reported
An additional 32 unique user accounts were compromised across 8 organizations, totaling 92 accounts in 41 hours.
Cyberscoop
2026-07-29
Huntress issues threat advisory
Huntress published a threat advisory detailing the credential stuffing campaign and its impact on SonicWall customers.
Cyberscoop

Community

Browse all →