SonicWall has officially implicated government hackers in the security breach September , which led to the unauthorized exposure of firewall configuration backup files .
See also: Increase in ransomware attacks on European organizations

“The malicious activity – carried out by a state-sponsored hacker – was limited to unauthorized access to cloud backup files from a specific cloud environment using API calls,” said in a statement released this week. “The incident is not related to the ongoing global Akira ransomware attacks on firewalls and other perimeter security devices.”
SonicWall: The investigation revealed involvement of state‑sponsored hackers
The revelation comes nearly a month after the company reported that an unauthorized party had gained access to firewall configuration backup files for all customers who used its cloud backup service. In September, the company said that hackers had gained access to backup files, stored in the cloud, for less than 5% of its customers.
See also: Russian Curly COMrades abuses Windows Hyper-V

SonicWall, which hired Mandiant to investigate the breach, said its products or firmware were not affected, nor were any of its other systems. It also said it has taken various corrective actions (recommended by Mandiant) to strengthen its network and cloud infrastructure, and will continue to improve its cybersecurity posture.
“As state-sponsored hackers increasingly target perimeter security providers, especially those serving small and medium-sized businesses and distributed environments, SonicWall is committed to strengthening its position as a leader for SMB partners and customers,” the company added.
See also: FIN7: Using Windows SSH Backdoor for remote access

SonicWall customers are encouraged to log in to MySonicWall.com to check their devices and reset credentials for affected services, if any. The company has also released an Online Analysis Tool and Credentials Reset Tool to identify services that require remediation and perform credential-related security tasks, respectively.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
