Skip to content
ThreatCluster

INC Ransomware Exploits SonicWall Vulnerabilities, Calls Victims Directly

First seen 6 Aug 2026, 07:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 7, 2026 at 03:27 UTC

The INC Ransomware group has exploited two critical vulnerabilities in SonicWall devices, specifically CVE-2026-15409 and CVE-2026-15410, affecting organizations in 71 countries, including Colombia. This campaign began three weeks prior to the patch release on July 14, 2026, and has reportedly impacted nearly 900 victims. Notably, INC Ransomware employed a unique tactic by calling victims directly to pressure them during extortion efforts. The vulnerabilities were publicly disclosed and patched by SonicWall, but active exploitation was confirmed to have started at least three weeks earlier. The attack vector primarily targeted SonicWall SMA 1000 devices, which are widely used in various sectors. The situation remains critical as organizations are urged to ensure their systems are updated to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2026-07-14
SonicWall patches released
SonicWall published patches for CVE-2026-15409 and CVE-2026-15410, addressing critical vulnerabilities.
Ciberseguridadlatam
2026-07-14
CVE-2026-15409 and CVE-2026-15410 added to CISA KEV
Both vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Ciberseguridadlatam
Recent
INC Ransomware campaign reported
The INC Ransomware group began exploiting SonicWall vulnerabilities three weeks before patches were available, affecting numerous organizations.
Ciberseguridadlatam

More articles in this cluster (3)

Following this threat?

Track INC, Sonicwall and CVE-2026-15409 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed