Ransomware Gangs Now Calling Victims: SonicWall Exploits and WhatsApp Hijacks

by The Creator | Aug 4, 2026

Ransomware response requires speed when attackers call directly after breaching your network. The INC gang is now exploiting SonicWall firewalls to enter systems, then using phone calls and social pressure to force ransom payments, while separate campaigns hijack WhatsApp accounts and distribute malware disguised as Adobe and Zoom updates.

Today's cybersecurity landscape shows attackers are getting more aggressive and personal. The INC ransomware group is exploiting SonicWall vulnerabilities and then calling victims directly to pressure them into paying ransoms. CISA has added a critical N-able N-central authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog after active exploitation was detected. WhatsApp users are falling victim to account hijacking through the linked devices feature, where scammers trick users into approving malicious device connections. A widespread campaign is distributing fake Adobe and Zoom updates that actually install ConnectWise ScreenConnect remote access tools. Russian threat actors are hijacking hotel Wi-Fi networks to steal cloud credentials from business travelers. The key takeaway: verify everything, patch immediately, use VPNs on public networks, and never download software updates from email links.

What ransomware response steps should your business take right now?

Four distinct attack vectors are active against SMBs this week. INC ransomware operators exploit SonicWall CVE-2024-40766 (a critical vulnerability) and call victims directly to accelerate payment. CISA added N-able N-central authentication bypass to its Known Exploited Vulnerabilities list after detecting active attacks. WhatsApp account hijacking spreads through linked devices, where attackers pose as contacts requesting device approval. Fake Adobe and Zoom installers deliver ConnectWise ScreenConnect malware. Your immediate actions: patch all internet-facing appliances (SonicWall, N-able agents) within 24 hours, disable linked devices on WhatsApp for all staff, block email links to software downloads, and require VPNs for all remote access and public Wi-Fi use. If you operate manufacturing or professional services, prioritize staff training on verification calls and update sources.

Key takeaways

  • SonicWall firewalls with CVE-2024-40766 are actively exploited; patch now and assume breach if unpatched.
  • INC attackers call after breach to pressure payments; hang up and contact CISA's 24/7 tip line and local law enforcement instead.
  • WhatsApp linked devices and fake software updates spread malware; block device links and disable auto-update on work devices.
  • Use a VPN on all public networks and require staff to verify software downloads through official vendor websites, never email links.

Frequently asked questions

If a ransomware attacker calls our business, what should we do?

Hang up immediately and do not engage. Document the call details (number, time, content) and report it to CISA at central@cisa.dhs.gov and your local FBI field office. Do not pay. Contact a ransomware recovery specialist or incident response firm before making any decisions.

How do we know if our SonicWall firewall is vulnerable?

Check your SonicWall version against CISA CVE-2024-40766. Versions before the patch are at risk. Log in to your appliance, note the firmware version, and apply the latest patch from SonicWall's update portal. If you cannot patch immediately, isolate the firewall or restrict access until patched.

Why are attackers calling victims after a breach?

Direct calls add urgency and psychological pressure to make victims pay faster, before IT teams discover the breach. Ransom negotiation by phone is harder to trace and creates a false sense of legitimacy. Treat any unexpected call from someone claiming to represent your security provider with skepticism and verify the caller independently.

What should we tell staff about fake software updates?

Train staff never to click download links in email, even from seemingly official sources. Direct them to vendor websites or internal IT for updates. Legitimate Adobe, Zoom, and Microsoft never ask you to download updates via email. When in doubt, call your IT provider.

Sources

Keep reading