INC ransomware, a prominent ransomware-as-a-service operation, has been identified as a primary threat actor exploiting a pair of recently disclosed SonicWall zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. While other actors engaged in exploitation prior to public disclosure, INC ransomware has been particularly effective in chaining these vulnerabilities to achieve data theft and encryption for extortion purposes.
The vulnerabilities were actively exploited for approximately three weeks before SonicWall disclosed and patched them on July 14. Initial exploitation, observed as early as June 22, utilized common hosted infrastructure and was largely unsuccessful. However, INC ransomware's confirmed activity, which began after the public disclosure, demonstrated a higher level of operational tempo and skill, moving rapidly from initial access to ransomware deployment.
Security researchers note that while INC ransomware is driving the post-disclosure wave of attacks, the full scope of exploitation cannot be attributed solely to this group. Rapid7, a security vendor, has reported successfully preventing data theft and encryption in the majority of recent cases they observed, though ransomware was deployed in at least one instance.
Since its emergence three years ago, INC ransomware has claimed nearly 900 victims across 71 countries. The group has listed several new alleged victims on its data leak site, including organizations and government agencies in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland. Some victims have reportedly received emails and phone calls from alleged hackers pressuring them into negotiations.
These latest zero-days add to a series of security challenges for SonicWall customers. Ten of the 17 SonicWall defects added to the Cybersecurity and Infrastructure Security Agency's (CISA) known exploited vulnerabilities (KEV) catalog since late 2021 are known to have been used in ransomware campaigns. Last year, a state-sponsored threat group reportedly stole firewall configurations from every SonicWall customer. More recently, researchers observed an attack spree that compromised 30 SonicWall customers in less than two days.






