The Akira ransomware group has begun weaponizing vulnerabilities in SonicWall SSL VPN devices, turning merger-and-acquisition (M&A) processes into high-speed launchpads for cyberattacks.
This trend exposes dangerous blind spots for businesses acquiring smaller companies, as inherited SonicWall devices often serve as easy entry points for attackers.
During mergers and acquisitions, acquiring companies often inherit IT infrastructure with outdated security practices.
Akira operators exploit these weaknesses, swiftly exfiltrating sensitive data and deploying ransomware.
According to Relia Quest, in recent incidents analyzed between June and October 2025, attackers gained initial access to larger enterprise networks using SonicWall SSL VPN appliances left over from smaller, acquired companies.
Once inside, Akira’s operators seek out privileged credentials, many of which are carried over during the M&A transition.
These credentials, usually unknown to the acquiring business and left unmonitored, provide rapid access to vital systems.
In some cases, attackers moved from initial compromise to a domain controller in just five hours, well before defenders could respond.
Small- and medium-sized businesses value SonicWall SSL VPNs for their affordability and ease of use. However, these benefits come with risks:
These factors make SonicWall devices reliable entry points for ransomware groups looking to exploit inherited security weaknesses.
Once Akira operators compromise a SonicWall device, they rapidly scan for high-value hosts.
Predictable naming conventions inherited from the acquired business make it easy for attackers to locate targets such as domain controllers and file servers.
In several cases, attackers exfiltrated data within minutes of gaining access, then laterally moved to deploy ransomware within an hour.
One particular weakness was inconsistent endpoint protection. Inherited networks frequently lacked modern EDR (Endpoint Detection and Response) solutions or had disabled protection.
Akira operators exploited these gaps by using DLL sideloading to disable defenses before encrypting systems.
The rapid adoption of SonicWall devices in smaller companies, paired with inherited security debt, creates complex risks during M&A:
Without rigorous asset discovery and credential hygiene, defenders are left vulnerable, with inherited weaknesses exposing the entire organization.
With fast-moving ransomware like Akira, early action is key to preventing devastating breaches and protecting sensitive data.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…