Huntress's Security Operations Center is tracking a fast growing credential stuffing campaign against SonicWall remote access devices. Analysts first flagged anomalous SonicWall login activity on July 25, 2026, and the number of confirmed compromises has climbed each day since, spreading across dozens of organizations. Huntress has traced the activity to a small cluster of IP addresses tied to a single hosting provider, consistent with automated tools that test large batches of leaked username and password pairs against internet facing login pages until one works. This is not a new tactic against SonicWall specifically. Huntress has now tracked comparable spikes against SonicWall SSL VPN products several times over the past year, which suggests attackers keep returning to the same target because it keeps working.
For a small Florida law firm, this matters even if you have never heard of SonicWall. Many firms rely on a firewall or SSL VPN appliance exactly like this one to let attorneys and staff log into the office network from home, from court, or from a client meeting. Credential stuffing succeeds because people reuse passwords. A password that leaked in an unrelated breach years ago, maybe from a retail account or an old email provider, can still be the same password protecting your firm's remote access today. Attackers are not guessing. They are simply trying stolen credentials at scale until one unlocks a door, and a firm's remote access appliance is one of the most valuable doors to unlock because it leads straight to case files, trust account records, and privileged communications.
Three things to check this week if your firm uses any SSL VPN or remote access appliance, from SonicWall or any other vendor. First, confirm multi factor authentication is enabled on every remote access login, not just email. If MFA is not already required, a single reused password is all it takes. Second, review your login logs for unfamiliar IP addresses or logins at unusual hours, and disable any remote access account that is not actively in use, including old employee or contractor accounts. Third, confirm your appliance firmware is current. Vendors regularly patch the exact weaknesses attackers are actively exploiting, and a device running old firmware is an easier target regardless of password strength.
Florida Bar Rule 4-1.6 already requires attorneys to make reasonable efforts to protect client information, and remote access is one of the most common paths into a firm's network. A campaign like this is a reminder that reasonable safeguards have to include the door your staff uses every day to work remotely, not just email and case management software.
ArisGate works exclusively with solo and small Florida law firms to close exactly these kinds of gaps before an attacker finds them first. Schedule a free security audit with us today and find out whether your firm's remote access is actually as protected as you think it is.