If you have ever bought a firewall for your office, there is a good chance it had a SonicWall sticker on the box. That is exactly why the news that broke in the fall of 2025 got so much attention. SonicWall, one of the most common firewall brands sold to small and medium businesses, confirmed that attackers had broken into the cloud service that stores customer firewall backup files. Here is what happened, in plain English, and what it should change about how you think about your own network.
What actually happened
In September 2025, SonicWall told customers that someone had broken into MySonicWall, the online portal where businesses store backup copies of their firewall settings. At first, the company said less than 5 percent of customers were affected. By October, after bringing in outside investigators, SonicWall had to walk that back. The real number was every single customer who had ever used the cloud backup feature.
Those backup files are not just harmless settings. They contain the blueprint of a business’s network: firewall rules, VPN configurations, and credentials for connecting other services like directory logins and remote access. Even though the files were encrypted, security researchers pointed out that a stolen blueprint of your defenses is valuable to an attacker whether or not they can read every line right away.
The attackers got in the old-fashioned way too, by repeatedly guessing passwords against SonicWall’s own backup system until one worked.
Why this matters even if you were never notified
Maybe your business was not on the list. That is good news, but it does not erase the bigger lesson here. A single vendor was holding the keys to hundreds of thousands of businesses’ network defenses in one place. When that one place gets broken into, every customer inherits the risk, whether or not they did anything wrong themselves.
This is the tradeoff that comes with a lot of traditional firewall setups. You buy the hardware, you are responsible for the updates, the backups, and the monitoring, and you are trusting that the vendor’s cloud portal is locked down tighter than your own front door. When it is not, you find out from a headline instead of from your IT person.
What a small business owner should actually take away from this
You do not need to become a cybersecurity expert overnight. You do need to ask a few honest questions:
-
Do you know who is responsible for updating your firewall, and how often it actually happens?
-
Are your network credentials rotated regularly, or have they been the same since installation day?
-
If your firewall vendor had a breach tomorrow, would anyone at your business know?
If the honest answer to any of those is “I’m not sure,” that is not a reason to panic. It is a reason to get a second set of eyes on your setup. Think of it like locking the back door before someone tries it, not after.
How AstraLink Connect approaches this differently
CONNECT is built and managed for you, not sold to you and left on a shelf. Updates, monitoring, and configuration are handled as part of the service, not as a task added to your to-do list. You can read more about how that works on our business page, or take a quick look at the Verify assessment if you just want a read-only checkup of what is actually happening on your network today.
See How CONNECT Protects Your Business →