Resecurity has named INC Ransomware the dominant exploiter of newly disclosed SonicWall SMA 1000 VPN flaws, with attacks accelerating since early August 2026. For UK IT teams still running SMA 1000 gateways, the question is no longer whether to patch — it's whether patching alone is enough after effective vulnerability management failed to keep pace with a zero-day campaign.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Suspected zero-day… | 0 | 4 |
| SonicWall patches released | 4 | 1 |
| INC ransomware acceleration | 5 | 3 |
What's happened to SonicWall SMA 1000 users
Resecurity's threat intelligence points to INC Ransomware as the group most actively weaponising a pair of SonicWall Secure Mobile Access (SMA) 1000 series vulnerabilities, with activity ramping up since the beginning of August 2026 and multiple named victims now appearing on the group's data leak site.
The attacks are suspected to chain CVE-2026-15409 and CVE-2026-15410 together to achieve arbitrary command execution on affected appliances — effectively handing an attacker full control of a device that was supposed to be the trusted front door for remote staff.
Patch status: fixed since mid-July, but exposure lingers
SonicWall released fixes for this vulnerability pair in mid-July 2026, so the patch itself is not the problem — it exists and has been available for weeks. The problem, according to Rapid7, is that the exploitation pattern is consistent with a zero-day campaign, meaning attackers were almost certainly using these flaws before a fix was ever published.
Rapid7's Douglas McKee summed up the forensic picture bluntly: "This strong technical correlation indicates that a single threat actor or coordinated group is responsible for discovering and exploiting this zero-day vulnerability." He added that the group behind it has since shifted decisively: "More recently, INC Ransomware has emerged as the dominant threat actor actively weaponizing this vulnerability chain."
For UK buyers, this is the uncomfortable pattern that keeps recurring with edge VPN gear: a vendor ships a fix, but any organisation that hasn't applied it — or that was already compromised before the patch existed — remains exposed. That's why effective vulnerability management has to include verification that patched devices haven't already been backdoored, not just confirmation that an update was installed.
Why INC's scale changes the risk calculus
INC is not a fringe operator experimenting with a new flaw. The group had already claimed no less than 830 victims since August 2023, according to earlier reporting, and the SonicWall SMA 1000 campaign has pushed its total claimed victim count to 885, with the most recent victim listed on 2 August 2026.
That trajectory — from 830 claimed victims through most of the group's history to 885 within weeks of a new exploit chain going public — tells UK buyers something important: INC treats a fresh, reliable remote-access vulnerability as a growth engine, not a one-off opportunity. Understanding how ransomware attacks have evolved this year helps explain why edge devices, rather than endpoints, are now the preferred entry point.

What attackers actually take once they're in
Rapid7's analysis found that intruders used their access to steal high-value credentials, active session databases, and TOTP MFA seed configurations — not just to get in once, but to maintain persistent access and move laterally across the network afterwards.
This is a materially worse outcome than a simple credential leak. Stolen session databases can let an attacker resume authenticated sessions without needing to log in again, and captured TOTP seeds undermine the very multi-factor authentication that many UK organisations rely on as their last line of defence. Any business that suspects exposure needs to strengthen your network security posture around session management and MFA re-enrolment, not just rotate passwords.
The wider credential-theft pattern around SonicWall gear
This isn't an isolated incident. A separate July 2026 credential-stuffing campaign against SonicWall-related VPN and firewall accounts affected 92 unique user accounts across 30 organisations, according to Huntress. INC has also been tied to other credential-theft activity, including the FortiBleed campaign, showing a consistent playbook of harvesting credentials from one edge device and reusing them for follow-on intrusions elsewhere.
For UK infrastructure teams, the takeaway is that VPN appliances are being treated as credential warehouses, not just access gateways. A single compromised SMA 1000 device can seed attacks well beyond its own network segment.
What a proper UK VPN audit looks like right now
Confirming the SonicWall patch is applied is the minimum bar, not the finish line. A credible audit in the current threat environment needs to cover four things: verifying patch levels against the mid-July 2026 fixes, forcing full credential rotation for any account that touched an SMA 1000 gateway, invalidating and reissuing active sessions rather than assuming they're clean, and re-seeding TOTP MFA configurations rather than trusting existing tokens.
Organisations that want to reduce their dependency on perimeter VPN appliances altogether should also weigh whether it's time to consider a VPN to ZTNA migration, since zero trust architectures limit the blast radius when — not if — an edge device is eventually compromised. Pairing that shift with managed detection & response gives UK teams a realistic chance of catching lateral movement before it reaches ransomware deployment, and reviewing broader ransomware protection strategies alongside a move to zero trust architecture closes the gap that INC is currently exploiting.
- 01The Hacker News — INC Ransomware Emerges as Dominant Threat Exploiting SonicWall SMA 1000 Flaws · 4 August 2026
- 02The Hacker News — INC Ransomware Claims 830 Victims Since August 2023 · 1 June 2026
- 03The Hacker News — FortiBleed Credential Theft Linked to Ongoing Campaigns · 1 July 2026
- 04The Hacker News — Threatsday: AI-Powered Hacking Roundup · 25 July 2026
