Find notable cyber news and cases, enriched with sources, timelines, and signals.

INC Ransomware campaign expands across multiple victims

Campaign
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countries. Newly listed victims and follow-on email and phone pressure tactics suggest the group is pairing exploitation with extortion. The activity has been tied to recent abuse of CVE-2026-15409 and CVE-2026-15410 against exposed appliances.

Related Happenings

SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)

Exploitation Wave
H score57 First: 03.08.2026 13:39 Last: 03.08.2026 13:39 Sources 1

How related: “Notably, as of the beginning of August 2026, INC Ransomware has accelerated its activity. Multiple new victims have been published on their Data Leak Site (DLS),”

About this happening: Attackers are conducting an active zero-day exploitation wave against SonicWall SMA1000 appliances using CVE-2026-15409 and CVE-2026-15410, creating takeover risk...

SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)

Vulnerability
H score48 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

How related: Patched on July 14 and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on the same day, the two flaws had been exploited in the wild as zero-days since at least June 22.

About this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against SMA1000 Secure Mobile Access appliances, with SonicWall...

Latest development: 03.08.2026 13:39

SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.

2025 Global cybercrime surge across credentials, ransomware, DDoS, and KEV exploitation

Trend
H score89 First: 29.04.2026 16:00 Last: 29.04.2026 16:00 Sources 1

About this happening: In 2025, global cybercrime activity intensified across compromised credentials, ransomware, DDoS, and KEV exploitation, raising risk for organizations worldwid...

Timeline

  1. 03.08.2026 13:39 2 articles · 1h ago

    INC Ransomware campaign expands across multiple victims

    Initial Disclosure

    By early August 2026, INC Ransomware had expanded its SonicWall SMA1000 exploitation activity and begun publishing additional victims on its leak site. The earliest visible phase of the campaign combined appliance compromise with direct extortion follow-up against newly affected organizations.

    Show sources