Security researchers report that the INC Ransomware group is exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. According to Resecurity, the group has accelerated its activity since the beginning of August 2026 and is listing multiple victims on its data leak site. The reporting characterizes INC as a leading or dominant actor in connection with these attacks.
SecurityWeek similarly states that INC ransomware targets vulnerable SMA1000 devices, using the SonicWall flaws to gain root access and carry out lateral movement within compromised environments. Across the accounts, the focus is on intrusions against SMA1000 appliances that have not been protected against the disclosed weaknesses.
While details of the specific technical exploitation steps and the full scope of affected organizations are not fully provided in the excerpts, both sources align on the core point: INC ransomware is actively leveraging SonicWall SMA 1000 vulnerabilities to compromise systems, expand access, and facilitate extortion-related victim disclosures.