Routine mergers and acquisitions are giving extortionists an easy way in, with Akira affiliates reaching parent networks through compromised SonicWall gear inherited in the deal, according to ReliaQuest. In every Akira attack the threat detection firm analyzed between June and October that involved buggy SonicWall SSL VPN appliances, the ransomware operators gained access to the bigger, acquiring enterprises because they had already compromised the smaller companies' SonicWall gear. "In these cases, the acquiring enterprises were unaware that these devices existed in their new environments, leaving critical vulnerabilities exposed," ReliaQuest threat intel analyst Thomas Higdon said in a Tuesday blog. Over the summer, Akira affiliates exploited buggy SonicWall firewalls and SSL VPN misconfigurations to gain access to vulnerable devices and conduct ransomware and data-stealing attacks. While the security shop says that it can't determine if the criminals were purposely targeting mergers and acquisitions, SonicWall SSL VPN devices are commonly used by small- and medium-sized businesses - and these are the types of companies likely to undergo an acquisition. Besides having M&A in common, all of the Akira ransomware infections also shared these three things: zombie privileged credentials, default or predictable hostnames, and a lack of endpoint protection. So if you don't want to fall victim to this or other ransomware operations - especially if your company is undergoing mergers...
Akira ransomware crew infected enterprise systems during M&A
The Register
·Jessica Lyons
·Published Nov 25, 2025
·Updated
Affected Software
2 affected components
SonicWall SSL VPN
SonicWall firewall
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how the Akira ransomware group exploits enterprise systems during mergers and acquisitions.
2
What security implications are discussed in the article?
The article highlights the risks of ransomware attacks exploiting compromised SonicWall devices inherited during M&A transactions.
3
What products or software are affected by the Akira ransomware group?
The affected software includes SonicWall SSL VPN and SonicWall firewall.
4
How do Akira affiliates gain access to enterprise networks?
Akira affiliates gain access through compromised SonicWall equipment that is acquired during mergers and acquisitions.
5
What timeframe does the article cover regarding Akira's attacks?
The article covers Akira's attacks analyzed between June and October of the publication year.