Threat Intelligence

INC Ransomware Gang Ramping Up Attacks on SonicWall VPN Flaws

The Hacker News · 4 Aug 2026
Key Takeaway If your business uses SonicWall SMA 1000 series VPN appliances, apply available security updates immediately and review remote access logs for signs of compromise.

Security researchers at Resecurity have identified the INC Ransomware operation as the most active group exploiting newly disclosed security flaws in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances. According to the report, the gang has significantly ramped up its activity since early August 2026, adding multiple new victims to its dark web data leak site.

VPN appliances are a common entry point for ransomware groups because they sit at the edge of a company's network and often provide direct access to internal systems once compromised. When vulnerabilities in these devices are disclosed, attackers move quickly to exploit unpatched systems before businesses can apply fixes, making rapid patching critical.

Australian small businesses using SonicWall SMA 1000 series devices should treat this as an urgent reminder to check their patch status and review remote access configurations. Ransomware groups like INC are known for both encrypting data and threatening to publish stolen information, putting both operations and reputation at risk.

ransomware VPN security SonicWall

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.