Prnewswire SonicWall Report Highlights Cyber Threats to Professional Services Firms
Article Content
- •Professional services firms faced 3 billion IPS events in H1 2026, the highest of any sector.
- •460 organizations in this sector are currently detecting ransomware campaigns.
- •MSP breaches can lead to access across multiple client networks, amplifying the impact.
SonicWall's 2026 Professional Services Protect Brief reveals that professional services firms, including law firms and managed service providers, experienced 3 billion IPS events in the first half of 2026, marking the highest attack volume across tracked industries. The report indicates that 460 organizations in this sector are actively detecting ransomware campaigns, emphasizing the unique vulnerability of client data due to accessible systems like client portals and document management platforms. Attackers exploit these vulnerabilities, targeting sensitive data such as legal records and financial transactions. The report highlights that breaches involving managed service providers (MSPs) can compromise multiple client networks simultaneously. Notably, ransomware families like Ryuk and Sodinokibi are specifically targeting these firms due to their access to critical data. SonicWall's findings are based on data from over one million security sensors globally, documenting attack patterns and exploitation vectors prevalent in the professional services landscape.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ryuk and Sodinokibi in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…
Ryuk Ransomware: Ongoing Threat to Large Organizations Ryuk ransomware, attributed to the Russian group Wizard Spider, continues to target large organizations, particularly in sectors like healthcare and government. The malware is delivered through phishing attacks and often relies on other malware like Emotet or TrickBot for initial access. Once inside a network, Ryuk…