INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.

Key points
- Two critical security flaws in SonicWall SMA1000 appliances (network devices companies use to let remote workers connect securely) were patched on 14 July 2026 after being exploited since at least 22 June.
- The INC Ransomware gang, which locks organisations out of their own files and demands payment, has emerged as the most active group using these flaws, with fresh victims posted to its public shaming site in early August 2026.
- Victims from the US, Australia, UAE, Colombia, and Switzerland have been listed on the gang's data leak site.
- After attacking organisations, criminals posing as helpers have been cold-calling victims and emailing them from suspicious addresses to apply extra pressure.
- The US cybersecurity authority CISA added both flaws to its official list of known exploited vulnerabilities on the same day the patches were released.
Two security holes found in SonicWall SMA1000 appliances, the hardware boxes many organisations plug into their networks so staff can connect securely from home, turned out to be far worse than most. The first flaw, CVE-2026-15409, carries a perfect severity score of 10 out of 10, meaning anyone on the internet could reach the device without a password and open a secret communication channel into parts of the network normally kept locked away. The second, CVE-2026-15410, scores 7.2 and lets that same attacker then promote themselves to the highest level of system control, known as root access, essentially becoming the device's owner.
Criminals had been quietly using both flaws since at least 22 June 2026, weeks before anyone published a patch.
How did the attacks work?
The attackers got in through the unpatched devices, then tried to spread deeper into victims' internal networks. Cybersecurity firm Rapid7 observed criminals moving from the SonicWall box into corporate systems, likely after planting a backdoor, a hidden access point they could return to later. A separate firm, Volexity, tracked one group stealing login credentials stored on the hacked devices.
SonicWall released fixes on 14 July 2026. That same day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaws to its Known Exploited Vulnerabilities catalogue, a public warning list that tells government agencies and businesses to patch immediately.
Should affected organisations be worried about the follow-up calls?
Yes, and this part is unusual. Cybersecurity firm Resecurity, which has been helping victims respond to the attacks, found that many organisations received suspicious emails and phone calls after being hit. A caller identifying himself only as "Andrew" claimed to represent a group of hackers and directed victims to email info@helprans[.]com. One email came from a domain that did not exist before the attacks began and was registered through a Chinese domain registrar. These are pressure tactics designed to confuse victims and extract further payment, not genuine offers of help.
| Detail | What we know |
|---|---|
| Flaws | CVE-2026-15409 (score 10), CVE-2026-15410 (score 7.2) |
| Product targeted | SonicWall SMA1000 remote-access appliance |
| Exploitation began | At least 22 June 2026 |
| Patch released | 14 July 2026 |
| CISA KEV added | 14 July 2026 |
| Most active attacker | INC Ransomware gang |
| Countries with known victims | US, Australia, UAE, Colombia, Switzerland |
In practice, the failure mode here is the same one it always is: internet-facing devices sitting unpatched for weeks while defenders wait for a maintenance window. One thing the post-mortem will say is that the patch was available; it just was not applied.
If your organisation uses SonicWall SMA1000 hardware, apply the July 2026 patches now and check logs for any unusual activity going back to late June. If anyone calls claiming to help with a ransomware problem you have not yet disclosed publicly, hang up and contact a verified incident-response firm directly.



