SonicWall has confirmed that an unauthorized actor gained access to and stole the entire repository of firewall configuration backup files from its cloud service.

The confirmation comes after the completion of an investigation by cybersecurity firm Mandiant, which determined that all customers who used the cloud backup feature were affected by the breach.
See also: ClayRat spyware turns phones into distribution hubs
The investigation revealed that threat actors were able to extract .EXP files, which are complete snapshots of firewall configuration data. These backups contain critical details about a network’s architecture, security policies, and encrypted credentials for various services. While SonicWall said that the credentials within the files remain encrypted, the broader configuration data is simply encoded, making it readable.
Security analysts warn that this provides attackers with a detailed blueprint of a target's security, significantly increasing the risk of future targeted attacks. With this information, threat actors could identify potential vulnerabilities in a network's setup and attempt to crack encrypted credentials offline (especially if weak passwords were used).

SonicWall's official response to the security incident
In response to the incident, SonicWall is notifying all affected partners and customers and has released tools to assist in assessment and remediation. The products affected by the security breach are SonicWall firewalls that used the cloud backup feature at MySonicWall[.]com.
See also: New hacker alliance Trinity of Chaos leaked data of 39 companies
Within the MySonicWall portal, the company has published updated lists of affected devices, which help customers prioritize remediation efforts by categorizing each device as “Active – High Priority” (internet-facing), “Active – Lower Priority” (internal-only), or “Inactive.”.
The company urges all customers to log in, locate their affected devices, and begin the recovery process.

SonicWall has implemented additional security enhancements across its infrastructure and is working with Mandiant to further enhance cloud security and monitoring systems to prevent similar incidents. The company is providingcustomers with a clear instruction: “Credential Reset Required.” Customers are urged to change all passwords and secrets for any service configured on the affected firewalls.
See also: AI Chatbot Abuse to Access Sensitive Data
To assist in this process, SonicWall has published a detailed “Remediation Guide” and a “SonicWall Online Tool” designed to analyze firewall configurations and identify all services that require credential updates. The company recommends prioritizing high-priority devices first. For customers who need assistance, a dedicated support team is available through the MySonicWall portal to guide them through the necessary changes and ensure their environments are secure.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
