ThreatCluster

INC Ransomware Exploits SonicWall Vulnerabilities, Calls Victims Directly

First seen 6 Aug 2026, 07:21 UTC Ciberseguridadlatam 93% similarity 70

Article Content

Browse articles
ThreatCluster

The INC Ransomware group has exploited two critical vulnerabilities in SonicWall devices, specifically CVE-2026-15409 and CVE-2026-15410, affecting organizations in 71 countries, including Colombia. This campaign began three weeks prior to the patch release on July 14, 2026, and has reportedly impacted nearly 900 victims. Notably, INC Ransomware employed a unique tactic by calling victims directly to pressure them during extortion efforts. The vulnerabilities were publicly disclosed and patched by SonicWall, but active exploitation was confirmed to have started at least three weeks earlier. The attack vector primarily targeted SonicWall SMA 1000 devices, which are widely used in various sectors. The situation remains critical as organizations are urged to ensure their systems are updated to mitigate risks.

Key Points: • INC Ransomware exploited SonicWall vulnerabilities CVE-2026-15409 and CVE-2026-15410. • The campaign affected nearly 900 victims across 71 countries, including Colombia. • Attackers called victims directly to pressure them during the extortion process.

ThreatCluster AI How this analysis works

Timeline

2026-07-14
SonicWall patches released
SonicWall published patches for CVE-2026-15409 and CVE-2026-15410, addressing critical vulnerabilities.
Ciberseguridadlatam
2026-07-14
CVE-2026-15409 and CVE-2026-15410 added to CISA KEV
Both vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Ciberseguridadlatam
Recent
INC Ransomware campaign reported
The INC Ransomware group began exploiting SonicWall vulnerabilities three weeks before patches were available, affecting numerous organizations.
Ciberseguridadlatam

Community

Browse all →

Tracked Entities in This Story