SonicWall Releases Advisory for Customers after Security Incident
Release Date: 22nd of September 2025
Impact : HIGH / CRITICAL
TLP Rating: Clear 
CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.
This alert is relevant to Organizations and individuals that utilize the above products. This alert is intended to be understood by technical users and systems administrators.
What is it?
SonicWall has released a security advisory to assist their customers with protecting systems impacted by the MySonicWall cloud backup file incident. SonicWall’s investigation found that a malicious actor performed a series of brute force techniques against their MySonicWall.com web portal to gain access to a subset of customer’s preference files stored in their cloud backup. While credentials within the files were encrypted, the files also included information that actors can use to gain access to customer’s SonicWall Firewall devices
TIP: Important Update
What are the Systems affected?
SonicWall Firewalls with preference files backed up in MySonicWall.com
What this means?
Actors can access file information to use to gain access to customer’s SonicWall Firewall devices
Mitigation process
CERTVU recommend all SonicWall Customers to log on into their customer account to verify whether their device is at risk. Customers with at-risk devices should implement the SonicWall advisory containment and remediation guidance immediately.
References
- https://www.cisa.gov/news-events/alerts/2025/09/22/sonicwall-releases-advisory-customers-after-security-incident
- https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330
- https://www.youtube.com/watch?v=LMkZJEIS1Ek
- https://psirt.global.sonicwall.com/vuln-list
- Download advisory (English): SonicWall Releases Advisory for Customers after Security Incident
- Download advisory (Bislama): SonicWall i Rilisim Advaesri blong ol Kastoma afta long wan Sekiuriti Insident
- Download advisory (French): SonicWall diffuse un avis à l’intention de ses clients après un incident de sécurité