SonicWall confirmed a breach dating to September 2025 in which firewall configuration backup files were stolen for all customers using its cloud backup service. The company later attributed the intrusion to a state-sponsored actor.
Reporting describes the exposed material as including usernames, passwords, private keys, site-to-site VPN configuration and administrative HTTPS settings.
A Firewall Config Is Not A Document, It Is A Blueprint
The configuration of a perimeter device describes the network behind it: which segments exist, what is permitted between them, which external partners have tunnels, which services are exposed and on what ports, and which administrative accounts exist.
That is the reconnaissance phase of an intrusion, completed in advance, for every customer of the service simultaneously — and it comes with credential material attached.
The Remediation Is Enormous And Mostly Not Done
This desk made the argument at Fortibleed in 26-0602: patching the device does not un-disclose the credentials it held. Here it is starker, because the exposure is not a defect in the device at all.
Proper remediation means rotating every credential and key in the configuration, across every affected device, plus reviewing whether the disclosed topology changes the risk assessment. That is weeks of work with user-visible disruption, and the incentive to declare it handled after applying an update is considerable.
Backing Up To The Vendor Was The Recommended Practice
Cloud configuration backup exists because restoring a failed appliance from a local copy nobody made is a common and painful failure. Customers who used the service were following good operational advice.
It is the shape this database keeps recording — at 25-0818, at 26-0127. A sensible centralisation creates a store whose compromise reaches every participant at once.
Compiled from the company’s disclosures and public reporting, listed below. The state-sponsored characterisation is the company’s own attribution as reported; no government is named. Corrections: corrections@forensicpost.com.