Summary is AI-generated, newsdesk-reviewed
  • Akira ransomware exploiting SonicWall VPN vulnerabilities, affecting global organisations.
  • Patch application alone insufficient; enforce MFA, reset passwords, hunt for threats.
  • Ransomware incursions disrupt services, highlighting crucial need for robust VPN security.

Global cyber risk consultancy S-RM has reported a sharp increase in ransomware incidents exploiting SonicWall firewall devices with SSL VPN enabled. The activity, tied to the Akira ransomware strain, is impacting organisations worldwide and has knock-on effects for everyday users.

The warning comes amid heightened national debate around the UK Government’s Online Safety Act and the security implications of VPN usage. S-RM says the latest attacks are a timely reminder that while VPNs can be essential security tools, poorly configured or incompletely patched VPN infrastructure can be a gateway for cybercriminals.

S-RM’s investigation

Key points from S-RM’s investigation include:

  • The Akira ransomware group is exploiting incomplete remediation of the earlier software vulnerabilities to gain initial access, even on devices that have been patched
  • Post-compromise tactics include privilege escalation on SQL servers, creation of local accounts, network reconnaissance, data exfiltration, and ransomware deployment
  • Files encrypted by Akira carry the extensions ‘.arika’ or ‘.akira’

Enterprise infrastructure breaches

Ted Cowell, Head of Cyber Security UK at S-RM, comments: “These cases show that patching alone is not a silver bullet. If you don’t reset credentials, enforce MFA across the board, and actively hunt for suspicious activity, you could already be compromised.”

“While the attacks are aimed at enterprise infrastructure, the fallout doesn’t stop there. Breaches can cause service outages, lock people out of online banking, delay healthcare appointments, or disrupt remote work. The message is simple: whether you’re a business or an individual, VPN security matters – and the Online Safety Act debate should remind us that how we configure and maintain these tools is just as important as whether we use them.”

S-RM urges all organisations using SonicWall SSL VPNs to:

  • Update firmware to the latest version
  • Reset all user and service account passwords
  • Enforce MFA for all accounts
  • Remove unused accounts
  • Conduct immediate threat hunting for signs of compromise

In case you missed it

How is the role of biometrics changing in physical access control?
How is the role of biometrics changing in physical access control?

Biometrics today provide better security and frictionless user experiences. Biometric identifiers like fingerprints, facial recognition, and iris scans are unique and difficult to...

dormakaba acquires Alliants for hospitality growth
dormakaba acquires Alliants for hospitality growth

dormakaba has signed a binding agreement to acquire Alliants Limited, the guest experience technology partner behind more than 100,000 hotel rooms for the world’s leading hos...

Allied Universal: Admired workplace in security industry
Allied Universal: Admired workplace in security industry

Allied Universal®, the world's pioneer security and facility services provider, has been named one of America's Most Admired Workplaces by Newsweek for the third consecutive ye...