Ongoing Akira ransomware attacks targeting SonicWall SSL VPN devices continue to evolve, with the threat actors found to be successfully logging in despite OTP MFA being enabled on accounts. Researchers suspect that this may be achieved through the use of previously stolen OTP seeds, although the exact method remains unconfirmed. In July, BleepingComputer reported that the Akira ransomware operation was exploiting SonicWall SSL VPN devices to breach corporate networks, leading researchers to suspect that a zero-day flaw was being exploited to compromise these devices. However, SonicWall ultimately linked the attacks to an improper access control flaw tracked as CVE-2024-40766 that was disclosed in September 2024. While the flaw was patched in August 2024, threat actors have continued to use credentials previously stolen from exploited devices, even after the security updates were applied. After linking the attacks to credentials stolen using CVE-2024-40766, SonicWall urged administrators to reset all SSL VPN credentials and ensure that the latest SonicOS firmware was installed on their devices. Cybersecurity firm Arctic Wolf now reports observing an ongoing campaign against SonicWall firewalls, where threat actors are successfully logging into accounts even when one-time password (OTP) multi-factor authentication is enabled. The report indicates that multiple OTP challenges were issued for account login attempts, followed by successful logins, suggesting that threat actors m...
Akira ransomware breaching MFA-protected SonicWall VPN accounts
BleepingComputer
·Lawrence Abrams
·Published Sep 28, 2025
·Updated
Affected Software
1 affected component
SonicWall SSL VPN
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Akira ransomware attacks breaching MFA-protected SonicWall VPN accounts.
2
How are the Akira ransomware attacks circumventing security measures?
The attacks are able to log in despite One-Time Password (OTP) MFA being enabled on accounts.
3
What specific product is being targeted by the Akira ransomware?
The affected software is the SonicWall SSL VPN.
4
What security implications are associated with these attacks?
The ability to breach MFA protections raises significant concerns about the robustness of current security measures.
5
What measures can organizations take to protect against such ransomware attacks?
Organizations should consider enhancing their MFA methods and monitoring for unusual login attempts to better protect against these evolving threats.