INC Ransomware Gang Ramping Up Attacks on SonicWall VPN Flaws
Security researchers at Resecurity have identified the INC Ransomware operation as the most active group exploiting newly disclosed security flaws in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances. According to the report, the gang has significantly ramped up its activity since early August 2026, adding multiple new victims to its dark web data leak site.
VPN appliances are a common entry point for ransomware groups because they sit at the edge of a company's network and often provide direct access to internal systems once compromised. When vulnerabilities in these devices are disclosed, attackers move quickly to exploit unpatched systems before businesses can apply fixes, making rapid patching critical.
Australian small businesses using SonicWall SMA 1000 series devices should treat this as an urgent reminder to check their patch status and review remote access configurations. Ransomware groups like INC are known for both encrypting data and threatening to publish stolen information, putting both operations and reputation at risk.