SonicWall has confirmed a significant escalation of a data breach first disclosed in September 2025. In an update on October 8, the network security vendor stated that an unauthorized third party successfully exploited a vulnerability in its MSW Cloud Backup API and exfiltrated firewall configuration backup files. Critically, the breach impacted every customer who has ever used the MySonicWall cloud backup service, a dramatic increase from the company's initial estimate that less than 5% of its firewall base was affected. The stolen configuration files (.EXP) contain a wealth of sensitive information, including firewall rules, security settings, and encrypted credentials. While SonicWall emphasizes that credentials remain encrypted, the incident provides potential attackers with a detailed blueprint of victim networks, significantly increasing the risk of future targeted attacks. The company is now notifying all customers and providing urgent remediation guidance.
The incident stems from the exploitation of an unspecified vulnerability in the API for the MySonicWall Cloud Backup platform. This allowed an unauthorized actor to systematically access and download .EXP backup files for the entire customer base of the service. These files are complete snapshots of a firewall's configuration.
The stolen data includes:
While SonicWall has stated that sensitive data like passwords are encrypted (using AES-256 on Gen 7 appliances), security experts warn that this is not a complete safeguard. Attackers in possession of both the configuration data and the encrypted values can mount offline attacks or use the configuration details to craft highly convincing social engineering campaigns. The investigation, supported by incident response firm Mandiant, is ongoing.
The primary attack vector was a compromised API endpoint. This is a classic example of a breach in a supporting cloud service leading to a compromise of customer data, bordering on a supply chain attack.
T1195.002 - Compromise Software Supply Chain: By compromising the cloud backup service, the attackers have acquired data that can be used to undermine the security of downstream customers.T1213.002 - Data from Cloud Storage: The core of the attack was the exfiltration of .EXP files from SonicWall's cloud infrastructure.T1526 - Cloud Service Discovery: Attackers likely probed SonicWall's cloud infrastructure to identify the vulnerable API endpoint.T1078 - Valid Accounts: The stolen configuration files could enable future attacks using valid, albeit potentially weak or brute-forceable, credentials.The impact of this breach is potentially severe for all SonicWall customers who used the cloud backup feature. Attackers now possess a detailed roadmap of their network architecture and security posture. This information can be used to:
SonicWall has categorized the risk to help customers prioritize, labeling internet-facing firewalls as "Active – High Priority." The breach erodes trust in SonicWall's cloud services and places a significant remediation burden on its entire customer base.
*.expMSW Cloud Backup APIAnomalous login attempts post-breachSince the breach occurred on SonicWall's infrastructure, customer-side detection of the initial event is impossible. Response efforts must focus on mitigating the consequences.
SonicWall has advised the following urgent actions, which align with D3FEND countermeasures:
SonicWall confirms state-sponsored actor behind September cloud backup breach, exploiting a compromised API call to steal customer firewall configurations.
Immediately reset all passwords and pre-shared keys associated with the firewall. Enforce strong, unique passwords going forward.
Mapped D3FEND Techniques:
Enable MFA for all administrative access to the firewall and for all remote access VPN users.
Mapped D3FEND Techniques:
Continuously monitor firewall logs for unauthorized access attempts, configuration changes, and other anomalous activity.
Mapped D3FEND Techniques:
Restrict management access to the firewall to a small, well-defined set of trusted IP addresses.
Mapped D3FEND Techniques:
Given that encrypted credentials were stolen, the most urgent countermeasure is mass credential eviction. All passwords for local users on SonicWall devices must be considered compromised and should be immediately reset. This includes administrative accounts, user accounts, and guest accounts. Furthermore, all pre-shared keys (PSKs) for site-to-site and client VPNs must be changed. This action directly invalidates the secrets stolen by the attackers, even if they manage to decrypt them. Automate this process where possible using configuration management tools. This is not just a password change; it's a forceful invalidation of all secrets contained within the stolen .EXP files to render them useless for direct authentication.
To defend against the future use of any potentially compromised credentials, implementing Multi-factor Authentication is a critical compensating control. MFA should be enforced for all administrative logins to the SonicWall management interface and, just as importantly, for all remote access VPN connections. Even if an attacker decrypts a user's password from the stolen configuration file, MFA will prevent them from successfully authenticating. Prioritize enabling MFA on high-priority, internet-facing firewalls first. This technique fundamentally strengthens authentication and provides a robust defense against attacks leveraging stolen static credentials.
The theft of configuration files provides attackers with a perfect blueprint of your network's defenses. Use this incident as an impetus to perform a full platform hardening review of all SonicWall devices. This involves more than just changing passwords. Audit every firewall rule to ensure it follows the principle of least privilege. Disable any unused services or protocols. Restrict management access to a dedicated, isolated management network or specific trusted source IPs. Ensure logging is enabled and configured to send to a central SIEM. By changing the very architecture the attacker has a map of, you invalidate their intelligence and increase the difficulty of a follow-on attack.
Approximate timeframe of the initial data breach disclosure by SonicWall.
SonicWall issues an update confirming all cloud backup users were impacted by the breach.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.