UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

INC Ransomware Dominates SonicWall SMA 1000 in 2026

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Resecurity has named INC Ransomware the dominant exploiter of newly disclosed SonicWall SMA 1000 VPN flaws, with attacks accelerating since early August 2026. For UK IT teams still running SMA 1000 gateways, the question is no longer whether to patch — it's whether patching alone is enough after effective vulnerability management failed to keep pace with a zero-day campaign.

SonicWall SMA 1000 exploitation timeline
W0W2W4W6W8Suspected zero-day…4wSonicWall patches released1wINC ransomware accelerati…3wTotal: 8 weeks end-to-end
View the data behind this chart
SonicWall SMA 1000 exploitation timeline
PhaseStarts (week)Duration (weeks)
Suspected zero-day…04
SonicWall patches released41
INC ransomware acceleration53

What's happened to SonicWall SMA 1000 users

Resecurity's threat intelligence points to INC Ransomware as the group most actively weaponising a pair of SonicWall Secure Mobile Access (SMA) 1000 series vulnerabilities, with activity ramping up since the beginning of August 2026 and multiple named victims now appearing on the group's data leak site.

The attacks are suspected to chain CVE-2026-15409 and CVE-2026-15410 together to achieve arbitrary command execution on affected appliances — effectively handing an attacker full control of a device that was supposed to be the trusted front door for remote staff.

Patch status: fixed since mid-July, but exposure lingers

SonicWall released fixes for this vulnerability pair in mid-July 2026, so the patch itself is not the problem — it exists and has been available for weeks. The problem, according to Rapid7, is that the exploitation pattern is consistent with a zero-day campaign, meaning attackers were almost certainly using these flaws before a fix was ever published.

Rapid7's Douglas McKee summed up the forensic picture bluntly: "This strong technical correlation indicates that a single threat actor or coordinated group is responsible for discovering and exploiting this zero-day vulnerability." He added that the group behind it has since shifted decisively: "More recently, INC Ransomware has emerged as the dominant threat actor actively weaponizing this vulnerability chain."

For UK buyers, this is the uncomfortable pattern that keeps recurring with edge VPN gear: a vendor ships a fix, but any organisation that hasn't applied it — or that was already compromised before the patch existed — remains exposed. That's why effective vulnerability management has to include verification that patched devices haven't already been backdoored, not just confirmation that an update was installed.

Why INC's scale changes the risk calculus

INC is not a fringe operator experimenting with a new flaw. The group had already claimed no less than 830 victims since August 2023, according to earlier reporting, and the SonicWall SMA 1000 campaign has pushed its total claimed victim count to 885, with the most recent victim listed on 2 August 2026.

That trajectory — from 830 claimed victims through most of the group's history to 885 within weeks of a new exploit chain going public — tells UK buyers something important: INC treats a fresh, reliable remote-access vulnerability as a growth engine, not a one-off opportunity. Understanding how ransomware attacks have evolved this year helps explain why edge devices, rather than endpoints, are now the preferred entry point.

Illustration: INC Ransomware Dominates SonicWall SMA 1000 in 2026

What attackers actually take once they're in

Rapid7's analysis found that intruders used their access to steal high-value credentials, active session databases, and TOTP MFA seed configurations — not just to get in once, but to maintain persistent access and move laterally across the network afterwards.

This is a materially worse outcome than a simple credential leak. Stolen session databases can let an attacker resume authenticated sessions without needing to log in again, and captured TOTP seeds undermine the very multi-factor authentication that many UK organisations rely on as their last line of defence. Any business that suspects exposure needs to strengthen your network security posture around session management and MFA re-enrolment, not just rotate passwords.

The wider credential-theft pattern around SonicWall gear

This isn't an isolated incident. A separate July 2026 credential-stuffing campaign against SonicWall-related VPN and firewall accounts affected 92 unique user accounts across 30 organisations, according to Huntress. INC has also been tied to other credential-theft activity, including the FortiBleed campaign, showing a consistent playbook of harvesting credentials from one edge device and reusing them for follow-on intrusions elsewhere.

For UK infrastructure teams, the takeaway is that VPN appliances are being treated as credential warehouses, not just access gateways. A single compromised SMA 1000 device can seed attacks well beyond its own network segment.

What a proper UK VPN audit looks like right now

Confirming the SonicWall patch is applied is the minimum bar, not the finish line. A credible audit in the current threat environment needs to cover four things: verifying patch levels against the mid-July 2026 fixes, forcing full credential rotation for any account that touched an SMA 1000 gateway, invalidating and reissuing active sessions rather than assuming they're clean, and re-seeding TOTP MFA configurations rather than trusting existing tokens.

Organisations that want to reduce their dependency on perimeter VPN appliances altogether should also weigh whether it's time to consider a VPN to ZTNA migration, since zero trust architectures limit the blast radius when — not if — an edge device is eventually compromised. Pairing that shift with managed detection & response gives UK teams a realistic chance of catching lateral movement before it reaches ransomware deployment, and reviewing broader ransomware protection strategies alongside a move to zero trust architecture closes the gap that INC is currently exploiting.

Share
Key takeaways
  • SonicWall fixed CVE-2026-15409 and CVE-2026-15410 in mid-July 2026, but exploitation is consistent with prior zero-day use, so patching alone doesn't confirm you weren't already compromised.
  • INC Ransomware has emerged as the dominant group weaponising this SMA 1000 chain, pushing its total claimed victims from 830 to 885 within weeks.
  • Stolen session databases and TOTP MFA seeds mean password resets are not sufficient — full session invalidation and MFA re-enrolment are required.
  • UK organisations should treat this as a trigger to review VPN exposure and evaluate a phased move towards zero trust network access.
Frequently asked

FAQs — INC Ransomware Dominates SonicWall SMA 1000 in 2026

Is the SonicWall SMA 1000 vulnerability still exploitable?

SonicWall released fixes for CVE-2026-15409 and CVE-2026-15410 in mid-July 2026. Devices that remain unpatched are still exploitable, and organisations that patched late may already have been compromised given evidence of prior zero-day exploitation.

How many victims has INC ransomware claimed?

The group's data leak site listed 885 victims to date as of the most recent update, with the latest victim added on 2 August 2026 — up from a previously reported 830 victims claimed since August 2023.

What data is at risk beyond login credentials?

Rapid7 found attackers stealing active session databases and TOTP MFA seed configurations alongside credentials, which allows persistent access and lateral movement even after passwords are changed.

Should UK businesses replace SonicWall SMA VPNs entirely?

The immediate priority is patching, credential rotation and session invalidation. Longer term, many organisations are reviewing whether to consider a VPN to ZTNA migration to reduce reliance on any single perimeter appliance.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111