INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward

A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries, then cold-calling victims to pile on the pressure.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of dark server racks, one rack visibly powered down with cables hanging loose, cool bl
Share

Key points

  • Two critical security flaws in SonicWall SMA1000 appliances (network devices companies use to let remote workers connect securely) were patched on 14 July 2026 after being exploited since at least 22 June.
  • The INC Ransomware gang has emerged as the most active group using these flaws, with fresh victims posted to its public shaming site in early August 2026.
  • Victims from the US, Australia, UAE and Colombia have been listed on the gang's data leak site, along with organisations from Switzerland.
  • After attacking organisations, criminals posing as helpers have been cold-calling victims and emailing them from suspicious addresses to extract further payment.
  • CISA added both flaws to its known exploited vulnerabilities catalogue on the same day the patches were released, 14 July 2026.

Two security holes in SonicWall SMA1000 appliances, the hardware boxes many organisations plug in so staff can connect securely from home, turned out to be far worse than most. The first flaw, CVE-2026-15409, carries a perfect severity score of 10 out of 10: anyone on the internet could reach the device without a password and open a WebSocket tunnel, a hidden communication channel, into parts of the network normally kept locked away. CVE-2026-15410, scoring 7.2, then lets that same attacker promote themselves to root, the highest level of system control, essentially becoming the device's owner.

Criminals had been quietly using both flaws since at least 22 June 2026, weeks before anyone published a patch.

How did the attacks work?

The attackers got in through the unpatched devices, then spread deeper into victims' internal networks. Rapid7 observed criminals pivoting from the SonicWall box into corporate systems, likely after planting a backdoor, a hidden access point they could return to later. Volexity, tracking the activity under the threat-actor label UTA0533, found that group harvesting login credentials stored on hacked devices, though it was less successful at moving laterally to other systems.

SonicWall released fixes on 14 July 2026. CISA added the flaws to its Known Exploited Vulnerabilities catalogue the same day. We've followed these devices since that patch dropped, with our 17 July report establishing INC Ransomware's early involvement and the subsequent 19 July story identifying UTA0533 as the group Volexity tracked.

Should affected organisations be worried about the follow-up calls?

Yes, and this part's unusual. Resecurity, which has been helping victims respond to the attacks, found that many organisations received suspicious emails and phone calls after being hit. A caller identifying himself only as "Andrew" claimed to represent a group of hackers and directed victims to email info@helprans[.]com. One email came from a domain registered after the exploitation activity began, through a Chinese domain registrar. These are pressure tactics designed to confuse victims, not genuine offers of help.

Detail What we know
Flaws CVE-2026-15409 (score 10), CVE-2026-15410 (score 7.2)
Product targeted SonicWall SMA1000 remote-access appliance
Exploitation began At least 22 June 2026
Patch released 14 July 2026
CISA KEV added 14 July 2026
Most active attacker INC Ransomware gang
Countries with known victims US, Australia, UAE, Colombia, Switzerland

The failure mode here is the same one it always is: internet-facing devices sitting unpatched for weeks while defenders wait for a maintenance window. The post-mortem will note the patch was available. It just wasn't applied.

If your organisation runs SonicWall SMA1000 hardware, apply the July 2026 patches now and check logs back to late June. Anyone calling to offer ransomware help you haven't requested is running a pressure play; hang up and contact a verified incident-response firm directly.

© 2026 Threat Vectr