INC Ransomware operators have seized on newly disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances to launch attacks against organisations worldwide. Resecurity identified INC as the dominant threat actor exploiting these flaws, with activity ramping up significantly since early August 2026.
SonicWall SMA 1000 devices function as remote access gateways for enterprises. The disclosed vulnerabilities create pathways for unauthenticated attackers to penetrate networks and establish persistence. INC exploits these weaknesses to gain initial access, then deploys ransomware payloads across victim infrastructure.
The threat group has already listed multiple victims on its data leak site, signalling active extortion campaigns. Resecurity's observation of accelerating INC activity suggests attackers discovered and weaponised the flaws rapidly after disclosure. This pattern reflects the race between defenders patching systems and criminals exploiting unpatched devices.
SonicWall SMA 1000 appliances serve as critical security perimeters for organisations allowing remote work. Compromise of these devices grants attackers direct access to internal networks, VPN credentials, and sensitive data. The combination of vulnerability disclosure and an organised ransomware group creates elevated risk for any organisation running unpatched SMA 1000 hardware.
Organisations using SonicWall SMA 1000 series appliances should prioritise patching immediately. Network defenders need to audit logs for indicators of compromise, monitor for lateral movement from gateway devices, and isolate affected systems if breach signs emerge. Enabling multi-factor authentication and restricting VPN access by role reduces attack surface even on unpatched systems.
INC Ransomware has targeted healthcare, finance, and manufacturing sectors previously. The group typically exfiltrates data before encrypting files, then demands
