- Home
- Alerts & Advisories
- Alerts
- Compromised SonicWall Backup Firewall Preference Files
Compromised SonicWall Backup Firewall Preference Files
22 September 2025
SonicWall has released security guidance following an investigation into suspicious activity targeting its cloud backup service for firewalls.
Background
SonicWall has released security guidance following an investigation into suspicious activity targeting its cloud backup service for firewalls.
Their investigations revealed that threat actors gained access to backup firewall preference files stored in the cloud. The breach impacted less than 5% of SonicWall's firewall install base. While the credentials within these files were encrypted, the files also included information that could make it easier for attackers to potentially exploit the related firewall.
Impact
The exposed backups could provide threat actors with access to sensitive information, such as credentials and tokens, for any or all services running on SonicWall devices on a network.
Affected Products
The incident affects SonicWall Firewalls that had preference files backed up in MySonicWall.com.
Mitigation
Users and administrators are advised to perform the following measures to determine if your firewall has been impacted by the incident:
Log in to your MySonicWall.com account and verify if cloud backups exist for your registered firewalls.
If the fields are blank: your firewall is not affected.

Figure 1: SonicWall firewall with no cloud backups
If the fields contain backup details: verify whether impacted serial numbers are listed in your account by navigating to Product Management | Issue List. The affected serial numbers will be flagged with information such as Friendly Name, Last Download Date and Known Impacted Services.

Figure 2: SonicWall firewall with cloud backups

Figure 3: SonicWall Issue List
If Serial Numbers are shown: the listed firewalls are at risk and should follow the containment and remediation guidelines provided by SonicWall here.
If you have used the Cloud Backup feature but none or only some of your registered Serial Numbers are shown: SonicWall will provide additional guidance to determine if your backup files were impacted, and additional information will be available here.
References
https://thehackernews.com/2025/09/sonicwall-urges-password-resets-after.html