# INC Ransomware Exploits SonicWall Vulnerabilities for Data Extortion

*Published August 5, 2026*
*Source: [https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/](https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/)*

## Executive Summary

The INC ransomware group has aggressively exploited SonicWall vulnerabilities disclosed in July, targeting organizations globally for data extortion. While Rapid7 has mitigated many attacks, the full impact and number of victims remain uncertain.

## Article

The INC ransomware group, known for its aggressive tactics, has been exploiting two zero-day vulnerabilities in SonicWall products, following their public disclosure and patching on July 14. Although they were not the first to target these flaws, INC has been the most prominent in using them to gain unauthorized access to systems. Brett Deroche, Director of Incident Response at Rapid7, highlighted that INC has been the most frequently mentioned threat actor in connection with these vulnerabilities since their disclosure. However, he cautioned against attributing all related attacks solely to INC.

SonicWall has faced a series of security challenges, with multiple zero-day vulnerabilities being actively exploited. In a recent attack spree, 30 SonicWall customers were compromised in less than two days, according to Huntress researchers. Notably, SonicWall vulnerabilities are frequently targeted by ransomware groups, with 10 out of 17 defects added to the Cybersecurity and Infrastructure Security Agency's catalog known to be exploited in ransomware campaigns since late 2021.

INC ransomware has made a significant impact since its emergence three years ago, claiming nearly 900 victims across 71 countries. Although the exact number of organizations affected by the latest SonicWall zero-days remains unclear, INC's confirmed activity escalated post-disclosure, demonstrating a rapid shift from gaining initial access to deploying ransomware. Rapid7 has managed to prevent data theft and encryption in most cases, but at least one incident resulted in successful ransomware deployment.

The scope of the attacks may extend beyond what Rapid7's telemetry has captured. INC has already listed several new victims on its data leak site, including entities in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. Resecurity has assisted several victims, who have reported receiving coercive emails and phone calls from the attackers.
