Friday, September 11, 2026

SonicWall Confirms Breach Exposing All Customer Firewall Configuration Backups

SonicWall, together with leading incident response firm Mandiant, has completed a thorough review of a recent cloud backup security incident.

The investigation confirmed that an unknown party gained access to all firewall configuration backup files for customers using the MySonicWall cloud backup feature.

These files contain encoded configuration settings and encrypted credentials. Although the credentials themselves remain protected by AES-256 encryption, the threat actor’s possession of these files could aid in crafting highly targeted attacks against affected networks.

SonicWall has updated final, comprehensive lists of impacted devices within the MySonicWall portal. Customers can find these lists under Product Management > Issue List.

Each device entry now shows an impact priority classification Active- High Priority for internet-facing units, Active-Lower Priority for non-internet-facing units, and Inactive for devices not checking in for over 90 days.

SonicWall is actively notifying all impacted partners and customers and providing tools to help assess and remediate exposed devices.

All SonicWall partners and customers are urged to log into their MySonicWall.com accounts immediately to verify whether any cloud backups exist for their registered firewalls.

If the backup fields are blank, customers can be confident their devices are not at risk. If backup details are present, customers should:

  1. Check the Issue List for flagged serial numbers, which include device name, last download date, and impacted services.
  2. Prioritize remediation starting with Active – High Priority devices, then Active – Lower Priority devices.
  3. Review and reset credentials for all services enabled at or before the backup timeframe.

Customers are directed to SonicWall’s Essential Credential Reset guide for containment and remediation steps.

Contains Backups
Contains Backups

A detailed Remediation Playbook is also available to walk through recovery procedures. SonicWall’s Online Tool for Firewall Config Analysis can identify specific services requiring credential reset.

Configuration backup files use the .EXP extension and contain a full snapshot of a firewall’s settings. Locally exported EXP files are only encoded, with credentials encrypted on modern SonicWall models.

 Impacted Services
 Impacted Services

Cloud backup files receive an additional layer of full-file encryption and compression before storage. When a user downloads a cloud backup from MySonicWall, the system decrypts the file and sends it over HTTPS in its encoded state, preserving credential encryption.

To strengthen defenses, SonicWall has implemented additional security hardening measures across its cloud infrastructure and monitoring systems.

The company continues collaborating with Mandiant to enhance detection controls and prevent future unauthorized access.

Customers with questions or requiring assistance should open a support case via the MySonicWall portal.

SonicWall will provide further guidance for customers whose backup fields or serial numbers do not appear in the current Issue List, ensuring every user receives clear instructions on verifying risk and responding to potential exposure.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News