INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward

A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of dark server racks, one rack visibly powered down with cables hanging loose, cool bl
Share

Key points

  • Two critical security flaws in SonicWall SMA1000 appliances (network devices companies use to let remote workers connect securely) were patched on 14 July 2026 after being exploited since at least 22 June.
  • The INC Ransomware gang, which locks organisations out of their own files and demands payment, has emerged as the most active group using these flaws, with fresh victims posted to its public shaming site in early August 2026.
  • Victims from the US, Australia, UAE, Colombia, and Switzerland have been listed on the gang's data leak site.
  • After attacking organisations, criminals posing as helpers have been cold-calling victims and emailing them from suspicious addresses to apply extra pressure.
  • The US cybersecurity authority CISA added both flaws to its official list of known exploited vulnerabilities on the same day the patches were released.

Two security holes found in SonicWall SMA1000 appliances, the hardware boxes many organisations plug into their networks so staff can connect securely from home, turned out to be far worse than most. The first flaw, CVE-2026-15409, carries a perfect severity score of 10 out of 10, meaning anyone on the internet could reach the device without a password and open a secret communication channel into parts of the network normally kept locked away. The second, CVE-2026-15410, scores 7.2 and lets that same attacker then promote themselves to the highest level of system control, known as root access, essentially becoming the device's owner.

Criminals had been quietly using both flaws since at least 22 June 2026, weeks before anyone published a patch.

How did the attacks work?

The attackers got in through the unpatched devices, then tried to spread deeper into victims' internal networks. Cybersecurity firm Rapid7 observed criminals moving from the SonicWall box into corporate systems, likely after planting a backdoor, a hidden access point they could return to later. A separate firm, Volexity, tracked one group stealing login credentials stored on the hacked devices.

SonicWall released fixes on 14 July 2026. That same day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaws to its Known Exploited Vulnerabilities catalogue, a public warning list that tells government agencies and businesses to patch immediately.

Should affected organisations be worried about the follow-up calls?

Yes, and this part is unusual. Cybersecurity firm Resecurity, which has been helping victims respond to the attacks, found that many organisations received suspicious emails and phone calls after being hit. A caller identifying himself only as "Andrew" claimed to represent a group of hackers and directed victims to email info@helprans[.]com. One email came from a domain that did not exist before the attacks began and was registered through a Chinese domain registrar. These are pressure tactics designed to confuse victims and extract further payment, not genuine offers of help.

Detail What we know
Flaws CVE-2026-15409 (score 10), CVE-2026-15410 (score 7.2)
Product targeted SonicWall SMA1000 remote-access appliance
Exploitation began At least 22 June 2026
Patch released 14 July 2026
CISA KEV added 14 July 2026
Most active attacker INC Ransomware gang
Countries with known victims US, Australia, UAE, Colombia, Switzerland

In practice, the failure mode here is the same one it always is: internet-facing devices sitting unpatched for weeks while defenders wait for a maintenance window. One thing the post-mortem will say is that the patch was available; it just was not applied.

If your organisation uses SonicWall SMA1000 hardware, apply the July 2026 patches now and check logs for any unusual activity going back to late June. If anyone calls claiming to help with a ransomware problem you have not yet disclosed publicly, hang up and contact a verified incident-response firm directly.

© 2026 Threat Vectr