DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

SonicWall Ransomware Attacks Offer an M&A Lesson for CSOs

By TheFinanceBase Team9 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The central M&A lesson from the 2025 SonicWall ransomware incidents is simple: an acquirer inherits more than systems and employees. It may also inherit undocumented firewalls, forgotten VPNs, former MSP accounts, unrotated credentials and network connections that no one realizes are still active.

ReliaQuest, as reported by CSO Online, linked Akira ransomware intrusions observed between June and October 2025 to SonicWall SSLVPN-connected environments. In the incidents described, devices had reportedly come from previously acquired smaller businesses, while the parent companies’ IT teams did not know the appliances remained deployed. Attackers then searched for privileged accounts associated with former administrators or managed-service providers.

The evidence supports a serious warning about inherited cyber risk. It does not prove that Akira affiliates selected every victim because of an acquisition, or that M&A itself caused the compromises. The defensible conclusion is narrower and more useful: an acquisition can leave behind an attack path that is technically connected, operationally forgotten and invisible to the parent company.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened in the SonicWall incidents

ReliaQuest’s reported analysis covered Akira ransomware activity involving SonicWall SSLVPN and firewall infrastructure from June through October 2025. The recurring pattern was reportedly an appliance inherited through an earlier acquisition, often involving a smaller business. The acquiring company’s IT team did not necessarily know that the device was still in its environment.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

That blind spot was compounded by identity risk. Old administrator, local VPN or MSP credentials were reportedly carried into the acquiring organization without being rotated, disabled or centrally monitored. After gaining access, attackers searched for privileged accounts and used the foothold to move deeper into the network.

The reporting has important limits. ReliaQuest reportedly did not disclose how many incidents it investigated and could not establish that the victims were targeted specifically because they had acquired companies with SonicWall devices. “Linked to,” “observed in” and “associated with” are therefore more accurate descriptions than “caused by M&A.”

Two SonicWall events must not be confused

There were two distinct SonicWall-related matters:

  1. Akira intrusions: SonicWall associated 2025 SSLVPN activity with the previously disclosed CVE-2024-40766 and with credential or configuration problems during device migrations.
  2. The MySonicWall cloud-backup incident: SonicWall later disclosed unauthorized access to firewall configuration backup files for customers using its cloud-backup service. SonicWall said that incident was unrelated to the Akira ransomware attacks.

The second event should not be presented as evidence that the cloud-backup service was the M&A-driven ransomware entry point.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2024-40766: a known vulnerability, not an unknowable zero-day

CVE-2024-40766 was an improper-access-control vulnerability in SonicOS management access. The National Vulnerability Database lists a CVSS 3.1 score of 9.8, or Critical, and records the vulnerability in CISA’s Known Exploited Vulnerabilities catalog.

The vulnerability was disclosed in August 2024, and CISA added it to KEV on September 9, 2024, with a federal remediation deadline of September 30, 2024. NVD’s recorded affected versions include SonicOS 5.9.2.14-12o and older, 6.5.4.14-109n and older, and 7.0.1-5035 and older, across affected Gen 5, Gen 6 and Gen 7 devices. Appliance and version applicability should be checked against the current vendor advisory.

CISA’s action was to apply vendor mitigations or discontinue use if mitigations were unavailable. It was not a universal instruction for every company to replace every SonicWall device.

SonicWall said the later activity was not a zero-day and correlated strongly with CVE-2024-40766. Its advisory also said it was investigating fewer than 40 incidents and that many involved Gen 6-to-Gen 7 migrations in which local user passwords were carried over and not reset.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The implication for CSOs is broader than “patch faster.” A patch cannot solve an asset no one knows exists. Nor does it revoke an administrator account that was migrated into a new appliance or inherited from a former MSP.

Why acquisitions create “unknown-knowns”

Traditional diligence often focuses on what the target says it owns and operates. The real attack surface may be larger:

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
  • Uncatalogued firewalls and VPN concentrators
  • Legacy network links and emergency tunnels
  • Former employee and MSP accounts
  • Shared service accounts and API keys
  • Unpatched or unsupported appliances
  • Cloud tenants, DNS providers and certificates
  • Remote-management tools and vendor-maintenance access
  • Configuration backups containing sensitive network data

A security questionnaire can accurately describe formal policies while omitting assets outside the documented program. That is the difference between a documented control environment and the actual connected attack surface.

M&A can also create a responsibility gap. The target believes the buyer now owns security. The parent assumes the target’s controls remain adequate until integration. The incumbent MSP assumes its access is temporary. Meanwhile, a VPN appliance or privileged account remains active.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The cybersecurity due-diligence checklist

1. Build an evidence-based asset inventory

Require a machine-verifiable inventory covering:

  • Internet-facing IP addresses, DNS records and certificates
  • Firewalls, SSLVPNs, IPsec VPNs and remote-access gateways
  • Cloud tenants, subscriptions and identity providers
  • Endpoint-management, EDR and remote-management platforms
  • Backup systems and network-configuration repositories
  • Network-to-network tunnels and third-party connections
  • OT, manufacturing and building-management systems where relevant
  • Technology inherited through earlier acquisitions

Use both inside-out and outside-in evidence. Inside-out evidence includes CMDB exports, network diagrams, vulnerability scans, identity records and configuration-management data. Outside-in validation includes attack-surface discovery, external scanning, certificate-transparency review and DNS enumeration.

NIST’s SP 1326 due-diligence guidance supports investigating available, pertinent information about suppliers, products and systems rather than relying solely on attestations.

2. Map every remote-access path

For every VPN, administrator portal, RDP gateway, RMM tool and vendor-maintenance account, ask:

  • Is it internet-facing?
  • Is MFA enforced for every user and administrator?
  • Are local accounts still enabled?
  • Were passwords reset after hardware or firmware migration?
  • Are former MSP and administrator accounts disabled?
  • Are authentication events centrally logged?
  • Can the target demonstrate a recent privileged-access review?

Do not accept “the company uses single sign-on” as an answer if local firewall, VPN, break-glass or service accounts remain active.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Test identity and credential hygiene

Obtain a privileged-account inventory with owners, last-login dates, MFA status, password-rotation evidence and offboarding records. Include local-device accounts, service accounts, API keys, certificates and secrets stored by MSPs.

A high-risk finding is an account with no clear owner, no recent business justification or a connection to a former employee or provider. Resetting employee passwords is not enough if firewall, VPN, service, API and MSP credentials are untouched.

4. Review patching and migration controls

Request current and historical vulnerability scans, remediation tickets, exception registers, firmware baselines and end-of-support reports. Pay particular attention to internet-facing appliances and devices imported from earlier acquisitions.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Ask for migration records showing whether local users, passwords, certificates, access rules and VPN settings were copied to replacement hardware. A patched device may still be unsafe if privileged credentials were transferred insecurely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Investigate latent compromise

Request incident-response reports, regulatory notifications, cyber-insurance claims, threat-hunting results, EDR and SIEM retention, unresolved forensic findings and known persistence mechanisms.

The question is not only “Has the target had a breach?” It is also “Can the target produce enough logs to support a credible answer?” A lack of notification is not proof that no compromise occurred, and a vulnerability is not proof that compromise occurred.

6. Examine MSP and third-party access

Review MSP, MSSP, RMM and vendor contracts. Identify shared credentials, persistent VPN access, subcontractors, privileged service accounts, breach-notification duties, audit rights and termination procedures.

The buyer should independently confirm that access has been removed. Do not rely only on the provider’s assertion that it has offboarded itself.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. Validate backups and recovery

Check whether backups are immutable or isolated, whether backup administration is separate from production identity, whether MFA protects backup consoles and whether restoration tests have succeeded.

Include firewall and network-device configuration backups in the review. SonicWall said the separate MySonicWall incident involved files containing encrypted credentials and configuration data. Encrypted configuration files can still increase targeted-attack risk if attackers obtain them, particularly when encryption keys, administrative access or migration processes are weak.

What to do between signing and closing

Signing does not make the target’s environment trusted, and closing should not automatically connect two networks. During the interim period:

  • Freeze new internet-facing exposure unless the acquirer approves it.
  • Require prompt notification of incidents, critical vulnerabilities and material configuration changes.
  • Preserve logs and forensic evidence.
  • Establish a joint incident-response contact tree.
  • Identify systems that must remain operational through closing.
  • Agree on minimum security conditions for network integration.
  • Define who pays for emergency replacement of unsupported appliances.
  • Use price adjustments, escrow, indemnity or remediation obligations for unresolved findings.

For sensitive technical data, a restricted-access or clean-room process may be appropriate. The deal team should also decide whether unresolved risks are conditions to closing or risks accepted with a specifically funded remediation plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Day 1: treat the acquired environment as untrusted

Until the risk is quantified, treat the acquired environment as an untrusted third-party connection. A practical Day 1 sequence is:

  1. Segment: Keep the target separate from the parent network and permit only approved connections.
  2. Inventory: Identify internet-facing devices, tunnels, cloud accounts, identities and third-party access.
  3. Disable: Remove unnecessary remote access, stale accounts, old tokens and obsolete administrator paths.
  4. Rotate: Reset local administrator, VPN, service and MSP credentials; rotate certificates, API keys and shared secrets.
  5. Enforce MFA: Apply it to users, administrators, VPNs, cloud consoles and backup systems.
  6. Centralize monitoring: Export firewall, VPN, identity, endpoint and cloud logs to the parent’s monitoring platform.
  7. Scan and hunt: Deploy EDR and vulnerability scanning, then investigate persistence, lateral movement and anomalous logins.
  8. Review rules: Examine firewall policies, inbound NAT, emergency tunnels and privileged access.
  9. Test recovery: Confirm that critical systems can be restored without relying on compromised production credentials.
  10. Approve integration: Set a documented deadline and evidence standard for moving from isolated connectivity to trusted integration.

These actions have trade-offs. Password resets can break automation, isolation can interrupt operations, and replacing legacy devices can create migration risk. Those costs should be planned—not used as reasons to connect an unverified environment.

Turning cyber findings into deal terms

Finding Possible transaction consequence
Unknown internet-facing VPN Immediate containment and delayed integration
Unsupported firewall Replacement funding, price adjustment or a closing condition
Active former-MSP account Immediate revocation and possible forensic investigation
No reliable asset inventory Independent assessment and a larger uncertainty reserve
Unresolved prior breach Escrow, indemnity, disclosure review and forensic diligence
Untested or weak backups Remediation funding and recovery requirements
No centralized logging Higher uncertainty about prior compromise and monitoring costs
Critical third-party dependency Contract review, continuity planning and integration sequencing
Unpatchable legacy system Segmentation, compensating controls or replacement

For the board, cyber diligence is not merely a technical report. Findings may affect whether to proceed, valuation, escrow, indemnity, insurance, integration timing, remediation budgets, disclosure obligations and executive accountability.

Public-company risk disclosures, including those in SEC filings, commonly recognize that acquisitions can introduce vulnerabilities that were not identified during diligence and may be difficult to integrate safely. That context is useful, but it is not a universal M&A rule or a substitute for transaction-specific legal advice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the SonicWall cases do—and do not—prove

  • They do show how known vulnerabilities can become more dangerous when assets and privileged accounts are invisible to the organization that inherits them.
  • They do not show that every Akira victim was selected because of M&A.
  • They do show why patching, credential rotation, MFA, logging, segmentation and asset ownership must be managed together.
  • They do not show that the MySonicWall cloud-backup incident was part of the Akira campaign.
  • They do show that a security certification or policy document is not proof of complete asset visibility.
  • They do not show that an independent assessment guarantees safety; it improves evidence and objectivity but cannot eliminate residual risk.

Security must be involved before the deal is signed

The strongest control is organizational: give the CSO or CISO a formal role in corporate development before signing, with authority to require evidence, independent testing and funded remediation.

That does not mean security leaders must personally perform every scan. An independent specialist can provide outside-in discovery, identity analysis, network review, forensic capability and a board-ready assessment. The provider should have M&A and carve-out experience, be independent of the target’s incumbent MSP and understand cloud, OT and third-party dependencies where relevant.

Products such as attack-surface discovery, vulnerability management, MDR, immutable backup and incident-response retainers can help. None solves the foundational problem alone. The acquirer first needs to know which assets, accounts and connections it actually owns.

The practical standard is therefore not “Is the target secure?” It is: Can we identify every path into the target, revoke inherited access, monitor the environment, recover critical systems and connect it to our network without accepting unexplained risk?

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.