INC Ransomware Exploits SonicWall Vulnerabilities, Calls Victims Directly
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The INC Ransomware group has exploited two critical vulnerabilities in SonicWall devices, specifically CVE-2026-15409 and CVE-2026-15410, affecting organizations in 71 countries, including Colombia. This campaign began three weeks prior to the patch release on July 14, 2026, and has reportedly impacted nearly 900 victims. Notably, INC Ransomware employed a unique tactic by calling victims directly to pressure them during extortion efforts. The vulnerabilities were publicly disclosed and patched by SonicWall, but active exploitation was confirmed to have started at least three weeks earlier. The attack vector primarily targeted SonicWall SMA 1000 devices, which are widely used in various sectors. The situation remains critical as organizations are urged to ensure their systems are updated to mitigate risks.
Key Points: • INC Ransomware exploited SonicWall vulnerabilities CVE-2026-15409 and CVE-2026-15410. • The campaign affected nearly 900 victims across 71 countries, including Colombia. • Attackers called victims directly to pressure them during the extortion process.