INC Ransomware Actively Exploits SonicWall SMA 1000 Vulnerabilities
The INC ransomware group is now the top threat exploiting known flaws in SonicWall's SMA 1000 VPN devices. Multiple organizations have been compromised and listed on the group's leak site.
TL;DR
- INC ransomware is the dominant actor exploiting SonicWall SMA 1000 vulnerabilities
- Attacks accelerated in August 2026 with multiple victims confirmed
- Organizations using unpatched SMA 1000 devices are at high risk
- Resecurity reports ongoing campaign with public victim listings
- Immediate patching and network monitoring are critical mitigations
A new ransomware operation called INC has rapidly become the primary threat actor exploiting security flaws in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances. According to security firm Resecurity, the group has significantly increased its activity since early August 2026.
Multiple organizations have already fallen victim to these attacks, with their names appearing on INC's data leak website. This development highlights the critical importance of promptly applying security patches to enterprise networking equipment, particularly remote access solutions that serve as common initial attack vectors.
Attack Details and Timeline
- INC ransomware began accelerating exploitation activities in early August 2026
- The group specifically targets CVEs in SonicWall SMA 1000 series VPN appliances
- Victims have been systematically listed on INC's public data leak site
- Resecurity's report indicates this is now the group's primary operational focus
Impact and Recommendations
- Organizations with unpatched SMA 1000 devices face immediate compromise risk
- Affected companies should review network logs for unauthorized access patterns
- SonicWall has released patches that must be applied immediately
- Security teams should monitor for lateral movement indicators following VPN breaches
- Consider implementing multi-factor authentication as an additional defense layer
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.