Executive Summary
In September 2025, SonicWall disclosed a cloud security incident that exposed firewall configuration backup files tied to less than 5% of MySonicWall accounts, prompting a company-wide advisory to reset credentials for impacted users. The breach involved unauthorized access to backup firewall preference files hosted in SonicWall’s cloud backup service, which could potentially allow attackers insight into sensitive network policies and infrastructure details. Upon detection, SonicWall revoked affected credentials, reset authentication tokens, and notified regulatory authorities and end-users. The incident underscores operational risks associated with cloud-based configuration repositories and the downstream consequences for enterprise security posture.
This breach highlights ongoing attacker focus on cloud storage services and device configuration files, which are increasingly targeted for initial access or lateral movement. As regulatory scrutiny grows and advanced threats seek out persistent footholds, organizations face mounting urgency to harden cloud storage, segment sensitive data, and enforce continuous credential hygiene.
Why This Matters Now
Cloud backup platforms remain high-value targets for cyber attackers, as misconfigurations or weak authentication can expose loosely protected device settings and credentials. The SonicWall breach reinforces the urgent need to secure cloud-stored infrastructure data and demonstrates how supply chain weaknesses can quickly impact thousands of enterprise customers.
Attack Path Analysis
Attackers initially compromised the SonicWall cloud backup service through unauthorized access to MySonicWall accounts, likely exploiting credential exposure or weaknesses. They escalated privileges within the environment to gain broader or admin-level access to stored configuration backups. The adversaries moved laterally within the cloud infrastructure, pivoting to gather multiple backup preference files from affected customers' resources. Command and control was maintained through cloud management interfaces, enabling ongoing malicious activity and access. Exfiltration occurred as attackers accessed and copied sensitive backup files from the cloud to external locations. The impact was exposure of firewall configurations, potentially enabling further attacks against customers relying on the compromised backups.
Kill Chain Progression
Initial Compromise
Description
Adversaries gained unauthorized access to the cloud backup service, likely by exploiting compromised user credentials or exploiting weak authentication on MySonicWall accounts.
Related CVEs
CVE-2024-40766
CVSS 9.6An improper access control vulnerability in SonicWall SonicOS allows remote attackers to gain unauthorized access to affected devices.
Affected Products:
SonicWall SonicOS – Gen5, Gen6, Gen7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Brute Force
Data from Cloud Storage Object
Account Discovery
Automated Exfiltration
Credentials from Password Stores
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Identity, Credential, and Access Management
Control ID: Identity Pillar - Implicit Trust Removal
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
SonicWall's cloud backup breach directly impacts security vendors' credibility and exposes firewall configurations, undermining zero trust segmentation and encrypted traffic capabilities.
Financial Services
Cloud security breach threatens PCI compliance requirements and encrypted traffic protection, potentially exposing critical firewall configurations for payment processing environments.
Health Care / Life Sciences
Firewall configuration exposure violates HIPAA requirements for data encryption and access controls, compromising patient data protection and east-west traffic security.
Government Administration
MySonicWall breach threatens NIST compliance frameworks and zero trust implementations, potentially exposing critical infrastructure firewall configurations to threat actors.
Sources
- SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customershttps://thehackernews.com/2025/09/sonicwall-urges-password-resets-after.htmlVerified
- MySonicWall Cloud Backup File Incidenthttps://www.sonicwall.com/pt-br/support/notices/mysonicwall-cloud-backup-file-incident/250915160910330Verified
- SonicWall Releases Advisory After Cybersecurity Incidenthttps://www.epa.gov/system/files/documents/2025-09/epa-ow-medium-cybersecurity-alert-sonicwall-releases-advisory-after-cybersecurity-incident.pdfVerified
- SonicWall breach: all firewall backups stolenhttps://cybernews.com/security/sonicwall-revises-breach-impact-all-firewall-backups-stolen/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
A CNSF-aligned Zero Trust approach leveraging segmentation, robust visibility, and policy-driven controls could have prevented lateral movement, detected anomalous activity, and minimized exfiltration risk by tightly restricting access to cloud backups and applying workload isolation and least privilege. CNSF controls like Zero Trust Segmentation, real-time anomaly detection, and egress filtering would have severely limited the adversary's progression across the kill chain.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Real-time policy enforcement and continuous assessment would have blocked or flagged illegitimate login attempts.
Control: Zero Trust Segmentation
Mitigation: Strict segmentation policies would have minimized blast radius and blocked privilege escalation attempts.
Control: East-West Traffic Security
Mitigation: Internal network controls would have prevented unrestricted access between workloads and regions.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous behaviors and command execution would be detected early and alerted for response.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data transfer to unauthorized destinations would be detected or blocked.
Comprehensive asset visibility and centralized control accelerates incident containment and remediation.
Impact at a Glance
Affected Business Functions
- Network Security
- Data Protection
Estimated downtime: 3 days
Estimated loss: $500,000
Unauthorized access to firewall configuration backup files containing encrypted credentials and configuration data, potentially facilitating targeted attacks.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access between sensitive cloud assets and enforce least-privilege policies.
- • Activate continuous Threat Detection & Anomaly Response for real-time identification of suspicious account activity or unauthorized data access.
- • Deploy Egress Security & Policy Enforcement to strictly control outbound data flows and block unapproved exfiltration attempts.
- • Enhance East-West Traffic Security to minimize attacker lateral movement opportunities within the cloud environment.
- • Leverage Multicloud Visibility & Control for instant oversight, rapid threat response, and comprehensive auditability across cloud resources.



