Menu
Browse

Cyber Incident Victim: SonicWall

Date:

Jan 2021

Location:

United States of America

Summary

A cybersecurity vendor experienced a breach of its internal systems by highly sophisticated threat actors exploiting probable zero-day vulnerabilities in its secure remote access products. The attack initially implicated NetExtender VPN clients and Secure Mobile Access (SMA) gateways, but subsequent investigation narrowed the focus to SMA 100 series appliances as the likely vectors containing unpatched vulnerabilities. Mitigations included restricting SMA device interactions via firewalls, disabling NetExtender VPN access, and enforcing multi-factor authentication for administrative accounts. This incident marked the fourth recent breach of a security vendor, following compromises at other major firms linked to the SolarWinds supply chain attacks, though the company's investigation did not confirm direct attribution to that campaign.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 3 techniques
Threat Actors Type Location
4 actors Available to members Available to members

Description

On January 23, 2021, SonicWall disclosed a security breach involving unauthorized access to its internal systems. The company described the incident as a "coordinated attack" by "highly sophisticated threat actors" who exploited probable zero-day vulnerabilities in certain SonicWall secure remote access products. Initial investigations implicated both NetExtender VPN clients and Secure Mobile Access (SMA) gateways as compromised entry points. However, within hours, SonicWall revised its assessment, narrowing the scope to SMA 100 series appliances as the sole products under active investigation for containing zero-day vulnerabilities. No patches were available for these vulnerabilities at the time of disclosure. The breach marked SonicWall as the fourth cybersecurity vendor to report a security incident within two months, following FireEye, Microsoft, and Malwarebytes—all of which had been compromised during the SolarWinds supply chain attack. Cisco and CrowdStrike had also been targeted in the SolarWinds campaign, though CrowdStrike reported unsuccessful intrusion attempts.

Cyber Incident Image

SonicWall responded by publishing mitigations in its knowledgebase to protect customer networks. These included deploying firewalls to restrict access to SMA devices, disabling NetExtender VPN client connectivity to firewalls, and enforcing two-factor authentication for administrative accounts. The company did not disclose the extent of internal network compromise or whether customer data was exfiltrated. Its advisory emphasized the ongoing nature of the investigation while urging customers to implement interim safeguards. The incident highlighted recurring targeting of security infrastructure providers, with SonicWall’s breach occurring amid a wave of high-profile attacks against vendors central to enterprise network defenses. No attribution or motive for the attack was provided in the disclosure.

Sources
Sources available to members
1 source