Cybercriminals are always adapting, and the latest surge in activity from the Akira ransomware group shows just how persistent and calculated these threats have become. In July 2025, a wave of attacks began targeting SonicWall SSL VPN devices, which are commonly used by businesses to support secure remote access for staff.
These attacks serve as a stark reminder: even well-maintained and up-to-date systems can be vulnerable without layered, proactive cyber defences in place.
What’s Happening with SonicWall VPNs?
According to threat researchers at Arctic Wolf Labs, several incidents have been traced back to unauthorised access via SonicWall VPN appliances. In a number of cases, devices were running the latest firmware, suggesting attackers may be exploiting a previously unknown vulnerability – commonly referred to as a zero-day.
That said, experts have not ruled out stolen credentials as an alternative entry point, especially if multi-factor authentication (MFA) is not enabled.
The rise in suspicious activity started around 15 July 2025, but retrospective analysis shows potential reconnaissance activity dating back to October 2024. This suggests that the threat actors – believed to be associated with the Akira group – have been testing and refining their tactics quietly for months.
The Akira Tactics: What Happens After Access Is Gained
Once Akira operators gain access to a network, their attack sequence usually follows a predictable but highly damaging pattern:
- Reconnaissance to map out the network and identify valuable systems
- Disabling of security tools to avoid detection
- Exfiltration of data for use in blackmail or resale
- Ransomware encryption of critical files
- Double extortion, threatening to leak stolen data if payment is not made
The group’s methods are known for being stealthy, methodical, and highly effective – especially when targeting environments where remote access is not tightly controlled.
What Should Businesses Be Doing Right Now?
If your organisation uses SonicWall VPNs, or any remote access solution, there’s no need for panic, but a heightened state of vigilance is essential.
Here are key steps to reduce your risk:
- Check for firmware updates and apply the latest patches from SonicWall immediately
- Enable multi-factor authentication (MFA) for all VPN users
- Review access permissions and restrict VPN use to essential users only
- Monitor for unusual login activity, such as logins at odd times or from unfamiliar locations
- Limit remote administrative access wherever possible
Even with patches in place, credential theft remains a key risk, so additional safeguards such as geofencing, IP allowlisting, and session monitoring are also worth exploring.
How Neuways Can Help
At Neuways, we take a proactive approach to threats like this. Our team monitors global threat intelligence and vendor updates so that we can identify and mitigate risks quickly on behalf of our customers.
Here’s how we help:
- Patch and vulnerability management to ensure systems stay secure
- Remote access hardening, including MFA enforcement and access control
- 24/7 monitoring and alerting for unusual activity on VPN and user accounts
- Security audits and risk assessments for remote working environments
- Incident response planning, so you know exactly what to do if something goes wrong
Whether you’re looking to strengthen your SonicWall setup or overhaul your entire remote access strategy, Neuways is here to help keep your business safe and connected.
The post SonicWall VPNs under attack: What businesses need to know appeared first on Neuways.