What happened
From 25 July 2026, security firm Huntress tracked an opportunistic credential-stuffing campaign against SonicWall VPN and firewall appliances, confirming 92 compromised accounts across dozens of organisations — every one using credentials leaked in previous, unrelated breaches.
The same week, Chick-fil-A disclosed that credential stuffing had compromised more than 13,000 customer loyalty accounts. And while stuffing works the front door, the INC Ransomware group was simultaneously exploiting two SonicWall SMA 1000 series vulnerabilities for full device takeover — with fixes only released in mid-July after zero-day exploitation was observed.
Why it matters to your business
73% of organisations have employee credentials sitting in breach dumps or infostealer logs, yet only 19% monitor for it. That combination is why credential stuffing remains the highest-return attack in the playbook: attackers simply try known email-password pairs against your VPN, email and cloud logins until one works.
Perimeter devices are the favourite target because a single working password is a door directly into the network. Your firewall or VPN appliance with a reused password and no MFA is, functionally, an unlocked office.
What you should do
MFA on every remote access point — VPNs, email, cloud consoles. Non-negotiable.
Screen credentials against breach databases so leaked passwords get reset before they're used against you.
Unique passwords via a password manager — the era of the memorable reused password is over.
Keep appliances patched and monitored. Device management with health monitoring catches both the unpatched appliance and the odd 2 a.m. login.