
INC Ransomware Now Leads in Attacks on Unpatched SonicWall SMA 1000 Gateways
The INC ransomware gang has become the primary threat abusing newly disclosed SonicWall SMA 1000 vulnerabilities, putting unpatched VPN appliances and the networks behind them at serious risk.
A wave of opportunistic attacks is targeting SonicWall Secure Mobile Access (SMA) 1000 series gateways, with the INC ransomware group emerging as the most active criminal actor exploiting the flaws. The vulnerabilities, which affect devices used to provide secure remote access into corporate networks, allow unauthenticated attackers to execute commands on affected appliances and gain a foothold inside protected environments. Once inside, attackers can move laterally, exfiltrate data, and deploy file-encrypting malware. Security researchers monitoring the situation report that threat actors began scanning for vulnerable SMA 1000 devices within hours of the flaws’ disclosure, and INC ransomware quickly became the dominant payload.
The targeted weaknesses stem from improper input handling in the SMA 1000’s web management interface. Although SonicWall has released software updates that plug the security holes, many organizations have not yet applied the patches. This delay gives ransomware gangs a reliable pathway to compromise networks hosting websites, databases, and critical business applications. Once encryption begins, victims face operational shutdowns and potential data leaks, as modern ransomware groups routinely threaten to publish stolen files unless a ransom is paid. The impact is especially severe for businesses that rely on these gateways for remote work and cloud connectivity.
For website operators and hosting providers, the consequences can be devastating. A compromised SMA 1000 can serve as a bridge into internal networks where web servers, content management systems, and customer databases reside. Ransomware actors often search for backup systems and network-attached storage, encrypting or wiping them to maximise pressure on victims. This underscores the need for defence-in-depth: perimeter appliances must be kept updated, network segmentation must limit lateral movement, and offline backups must be regularly tested. Additionally, monitoring outbound traffic for indicators of exfiltration can help detect breaches before encryption starts.
AEU Hosting’s managed WordPress platform incorporates proactive security hardening and continuous monitoring that help detect and block malicious activity early, reducing the risk that a compromised edge device on a client’s network leads to a full-blown ransomware incident. Still, no service can replace fundamental security practices. Immediately upgrading all SonicWall SMA 1000 appliances to the latest firmware is the most critical step. Organisations should also review access controls, disable unnecessary services, and ensure that remote management interfaces are not exposed to the public internet without strong authentication. By combining patching, network segmentation, and resilient backup strategies, businesses can significantly lower their exposure to ransomware gangs like INC.
How to Protect Yourself
- Apply the latest firmware updates from SonicWall to your SMA 1000 device right away—this closes the security gaps that attackers use.
- Turn on automatic updates where possible, and set a recurring calendar reminder to check for and install any new patches.
- Make frequent backups of your website and databases, and store at least one copy completely offline or on a separate network so ransomware cannot reach it.
- Use multi-factor authentication for any remote access to your network or hosting control panel, so a stolen password alone is not enough to break in.
- If you are not sure whether your device is patched, ask your IT team or hosting provider to verify and apply the latest updates immediately.