Summary is AI-generated, newsdesk-reviewed
  • Akira ransomware exploits SonicWall SSL VPNs, spiking global cyberattack incidents on organizations.
  • Resetting credentials, enforcing MFA, and timely updates essential for VPN security.
  • S-RM: Poorly configured VPNs risk breaches that disrupt banking, healthcare, and remote work.

Global cyber risk consultancy S-RM has reported a sharp increase in ransomware incidents exploiting SonicWall firewall devices with SSL VPN enabled. The activity, tied to the Akira ransomware strain, is impacting organizations worldwide and has knock-on effects for everyday users.

The warning comes amid heightened national debate around the UK Government’s Online Safety Act and the security implications of VPN usage. S-RM says the latest attacks are a timely reminder that while VPNs can be essential security tools, poorly configured or incompletely patched VPN infrastructure can be a gateway for cybercriminals.

S-RM’s investigation

Key points from S-RM’s investigation include:

  • The Akira ransomware group is exploiting incomplete remediation of the earlier software vulnerabilities to gain initial access, even on devices that have been patched
  • Post-compromise tactics include privilege escalation on SQL servers, creation of local accounts, network reconnaissance, data exfiltration, and ransomware deployment
  • Files encrypted by Akira carry the extensions ‘.arika’ or ‘.akira’

Enterprise infrastructure breaches

Ted Cowell, Head of Cyber Security UK at S-RM, comments: “These cases show that patching alone is not a silver bullet. If you don’t reset credentials, enforce MFA across the board, and actively hunt for suspicious activity, you could already be compromised.”

While the attacks are aimed at enterprise infrastructure, the fallout doesn’t stop there. Breaches can cause service outages, lock people out of online banking, delay healthcare appointments, or disrupt remote work. The message is simple: whether you’re a business or an individual, VPN security matters – and the Online Safety Act debate should remind us that how we configure and maintain these tools is just as important as whether we use them.”

S-RM urges all organizations using SonicWall SSL VPNs to:

  • Update firmware to the latest version
  • Reset all user and service account passwords
  • Enforce MFA for all accounts
  • Remove unused accounts
  • Conduct immediate threat hunting for signs of compromise

In case you missed it

How Are New Technologies Reshaping Casino Surveillance And Security?
How Are New Technologies Reshaping Casino Surveillance And Security?

Casinos are tasked with monitoring vast gaming floors, cashier cages, and access points. The market for casino security and surveillance demands software and hardware that provide...

HID Enhances Mobile Access For Digital Transformation
HID Enhances Mobile Access For Digital Transformation

HID, a pioneer in trusted identity solutions, announces new enhancements that help organizations fast-track their mobile access adoption as part of their broader digital transforma...

Fifth Third Bank Security Strategy With March Networks
Fifth Third Bank Security Strategy With March Networks

The challenge: Fifth Third Bank is one of America’s largest and fastest-growing financial institutions, with more than 1,500 financial centers and approximately 80 high-rise,...