SonicWall is warning administrators that recent brute force attacks on its firewall's cloud backup API service may have exposed backup configuration files stored on its cloud portal.

SonicWall firewalls with preference files backed up to the customers' MySonicWall.com portal are affected
In response, access to the backup feature has been disabled and administrators are asked to disable or restrict access to the SSLVPN service and Web/SSH Management over the WAN. In addition, they must reset passwords, keys, and firewall secrets.
Passwords and keys may also need to be changed elsewhere, such as at the organization's ISP , dynamic DNS provider, email provider, remote IPSec VPN peer, or LDAP/RADIUS server. SonicWall offers complete instructions on its website.
If a customer has used the cloud backup feature but does not have any serial numbers in their MySonicWall account, SonicWall will provide additional instructions in the coming days.
See also: Python-based XillenStealer attacks Windows users
SonicWall said that “less than 5% of our firewall install base had backup firewall preference files stored in the cloud.” It said it has 500,000 customers, but not all of them subscribe to its firewalls. However, again, the 5% estimate could translate to thousands of organizations.
"While the files contained encrypted passwords, they also included information that could make it easier for attackers to potentially exploit firewalls," SonicWall said.
“Having the backup is like a treasure trove of puzzle pieces that you can piece together to see the security posture and general network access of the backed-up device,” warned Kellman Meghu, security architect at Canadian incident response firm DeepCove Cybersecurity.

"No ransomware," says SonicWall
To date, the company has found no evidence that these files have been leaked online by malicious actors.
"This was not a ransomware incident or anything similar," the statement said. "Rather, this was a series of brute force attacks per account, aimed at gaining access to preference files stored in backups for possible further use by malicious actors."
See also: Over 40,000 cyberattacks target API environments
Users of the MySonicWall.com portal should log in and check if cloud configuration backups. The serial numbers of affected devices are listed for those using the feature, so each customer's portal will be highlighted with an information banner.
Wednesday's warning comes after several national cybersecurity authorities warned that the Akira ransomware gang is exploiting SonicWall firewalls that have not installed a 2024 update for a critical vulnerability.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What are brute force attacks?
Brute force attacks attempt to crack passwords, login credentials, and encryption keys. They've been around since the dawn of computing, but they're still effective. Why? Partly because people still use easy passwords like '1234', or their company name, or default passwords left on hardware and software by vendors.

Malicious actors have compiled lists of the most commonly used passwords (names of famous athletes, names of famous actors, names of famous rock bands…), based on years of data breaches, which they sell or share for use in what are called credential-stuffing.
See also: RevengeHotels leverages AI to distribute VenomRAT
A dictionary uses a list of words from a dictionary. Hybrid brute force attacks combine a dictionary with lists of stolen passwords . Modern computing technology also helps malicious actors, Meghu pointed out. With today's low-cost cloud computing resources, any crook can create a temporary virtual machine to try each combination against a file.
And Picus Security recently reported that even hashed passwords can be easily cracked.
Defenses
- Customers should use long passwords of at least 16 letters and numbers.
- Encourage employees to use a key phrase they can remember.
- To discourage users from creating easy passwords, CSOs should require employees to use a password manager to store their credentials.
- Experts advise that the best defense against brute force attacks is phishing-resistant multi-factor authentication (including the use of physical USB keys or biometrics as an additional login step).
