VYPR
breachPublished Jul 29, 2026· 1 source

Huntress Warns of Rapid Credential Stuffing Attacks Targeting SonicWall Customers

Huntress reports a swift credential stuffing campaign that compromised 30 organizations and 92 user accounts on SonicWall VPN and firewall devices within two days.

Cybersecurity firm Huntress has identified an aggressive and ongoing credential stuffing campaign that rapidly compromised 30 organizations and 92 user accounts across various SonicWall VPN and firewall devices. The attacks, which began on a Saturday, escalated quickly, with the majority of compromises occurring within a 41-hour period. Researchers noted that the campaign was broad and opportunistic, targeting a diverse range of SonicWall devices rather than focusing on specific models or industries.

As of press time, SonicWall had not issued a formal security advisory regarding the activity, stating they were still investigating. The attacks ceased as abruptly as they began, with the last observed compromise occurring on Monday. This pattern suggests a potential rotation of attacker infrastructure, a common tactic to evade detection and prepare for future operations.

Crucially, the unidentified attackers have refrained from any post-compromise activity, leading Huntress to believe these intrusions are likely pre-positioning for more significant future attacks. "With local network access, the sky is essentially the limit for most networks that do not have proper topology controls in place," stated Michael Tigges, principal tactical response analyst at Huntress.

Huntress's observations are based on telemetry from its own customer base, meaning the total number of affected organizations could be higher. The initial vector for these attacks involves the use of authorized login credentials. Attackers are systematically validating these credentials against remote access portals to maximize account compromises.

The source of these stolen credentials remains unconfirmed but could stem from various origins. Potential sources include aggregated logs from infostealer malware, previously compromised SonicWall configuration files, or credentials harvested from past vulnerabilities that were not fully utilized at the time of their discovery.

This incident adds to a history of security challenges for SonicWall customers. In 2025, a state-sponsored actor compromised SonicWall's cloud environment, exfiltrating customer firewall configurations. Furthermore, SonicWall devices have been repeatedly targeted by actively exploited zero-day vulnerabilities, with 17 defects affecting the vendor's products added to CISA's Known Exploited Vulnerabilities (KEV) catalog since late 2021.

"Edge devices are one of the most targeted interfaces, comprising over 70% of active intrusions triaged by Huntress, including the overwhelming majority of ransomware deployments," Tigges explained. He emphasized the critical need for organizations to invest in robust secure remote access solutions and resilient network architectures to mitigate the ongoing risks associated with edge device compromises.

The opportunistic nature of these attacks underscores the persistent threat posed by credential stuffing and the importance of strong, unique passwords, multi-factor authentication, and vigilant monitoring of remote access points. Organizations using SonicWall devices are advised to review their security configurations and monitor for any unusual login activity.

Synthesized by Vypr AI