
The fastest way into a small business right now is the VPN built into its own firewall. Attackers log in through the SSL-VPN with valid credentials, skip the email filter and the endpoint agent entirely, and start encrypting. The Akira ransomware crew has turned this into an assembly line against SonicWall appliances, and the timeline is brutal.
Arctic Wolf tracked one Akira campaign where ransomware encryption happened in under four hours from initial access, with a staging interval as short as 55 minutes in some cases. That's not enough time to notice, call your IT provider, and react. By the time anyone sees the ransom note, the backups are already a question mark.
If your business relies on a firewall VPN for remote access, this is your problem too, whether you run SonicWall or not.
How does the attack actually work?
Attackers authenticate to the SSL-VPN with credentials they already hold, then move fast. They don't break down the door. They walk through it with a key, scan the internal network, reach for domain admin, and deploy ransomware before the dwell time gets measured in days.
Huntress reported one wave in early October 2025 where over 100 SonicWall SSL-VPN accounts across 16 customer environments were accessed in a two-day span. The logins looked legitimate because, mechanically, they were. Valid username, valid password, and in related SonicWall campaigns attackers bypassed multi-factor authentication without tripping login alerts.
Where do the credentials come from? Old breaches, infostealer malware on an employee's home PC, and firewall config data that leaked in a separate SonicWall cloud-backup incident. Once a password is out, an internet-facing VPN portal is a standing invitation.
Why do attackers love the firewall VPN specifically?
The firewall VPN sits outside the tools you paid to protect you. Your email security, your endpoint detection, your DNS filtering — none of them watch the SSL-VPN login page. It's exposed to the entire internet by design, it authenticates straight into your network, and on older appliances it logs almost nothing useful.
Edge devices — firewalls, VPN gateways, remote-access appliances — have become the preferred ransomware entry point precisely because they're forgotten. Nobody patches the firewall on the same cadence as the laptops. It just runs.
What does a small business do about it right now?
Assume the credentials are already out and shut the easy paths first. Four moves, in order:
- Patch the appliance and check end-of-life. Older SonicWall Gen6 firewalls are moving into retirement and losing security fixes. If your appliance is out of support, it's a liability, not an asset — replace it.
- Force a full password reset for every VPN account and kill any local firewall accounts you don't recognize. Old credentials are the whole game here.
- Turn on MFA and verify it actually enforces. Several of these intrusions walked past MFA that was configured but not working. Test it, don't assume it.
- Stop trusting the VPN as a flat tunnel into everything. Move toward zero-trust network access, which checks the user and device on every request instead of handing out the whole network after one login.
Longer term, the fix is architectural. A firewall VPN grants broad access after a single authentication. That model is the reason a stolen password turns into a company-wide encryption event in under an hour.
How fast could this hit us?
Fast enough that detection alone won't save you. With encryption starting inside an hour of access in the worst cases, your defense has to be prevention at the door plus recovery you've actually tested. Tested, offline backups are what decide whether a bad morning is a cleanup or a shutdown.
If you don't know when your firewall was last patched, who has VPN accounts, or whether your backups restore, that's the assessment to run this week. A managed security review answers all three.
By Joel Baum. The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Frequently asked questions
Is this only a SonicWall problem?
No. SonicWall SSL-VPNs took the brunt of the Akira campaigns, but the pattern — stolen credentials used against an internet-facing VPN portal — applies to any firewall VPN. Fortinet, Cisco, and others have all been targeted through the same door. The vendor matters less than the exposure.
We have MFA on our VPN. Are we safe?
Not automatically. Several of these intrusions bypassed MFA that was configured but misapplied, or defeated it with credential and session theft. MFA is necessary and not sufficient. Verify it enforces on every account, and pair it with patching and least-privilege access.
How would we even know we were breached?
Watch for VPN logins from unfamiliar countries or IP addresses, off-hours authentications, and sudden internal network scanning. Older appliances log little, so many businesses find out only when files encrypt. Centralized logging and a monitored SOC catch it far earlier.
Should we replace the firewall VPN entirely?
Consider it. Zero-trust network access removes the single-login-to-everything weakness that makes these attacks so fast. You don't have to rip anything out this week, but if your appliance is end-of-life, replacement and a ZTNA move should be on the near-term plan.
What's the first thing to do today?
Reset every VPN credential and confirm your firewall is patched and still supported. Those two steps close the paths being exploited right now. Then book a review of your backups and remote-access design so a single stolen password can't take down the business.
Worried your remote access is the weak point? Contact The NetSys Group for a complimentary risk assessment of your firewall, VPN, and backups.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



