Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking

Imported from official source

Cybersecurity Classified by Officially

Since July 25, Huntress has observed an active, broad, and opportunistic credential stuffing campaign resulting in successful unauthorized logins to SonicWall VPN and firewall accounts. So far, 30 organizations have been impacted.

The activity stems from five IPs and relies on infrastructure hosted on DigitalOcean to compromise numerous, seemingly unrelated organizations.

Current telemetry indicates this is an automated credential validation attack, consistent with similar campaigns targeting SonicWall VPNs throughout 2025 and 2026.

Organizations utilizing SonicWall infrastructure should immediately review authentication logs, disable affected accounts, and ensure multi-factor authentication (MFA) is strictly enforced.

Acknowledgments: Special thanks to Andrea Ochoa, Cristian Poenaru, Harry Godridge, Rob Stynes, Joshua Kiriakoff, Jordan Sexton, Anthony Gibbs, Austin Worline, Michael Tigges, Tyler Bohlmann, and Nick Roddy for their contributions to this investigation and response.

Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. 

Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations.

Our telemetry indicates that the threat actors are leveraging a specific set of infrastructure to conduct these credential stuffing attempts. We have identified five primary malicious IP addresses driving this attack, all of which are registered to DigitalOcean, LLC:

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.