Ransomware hackers attack SMBs being acquired to try and gain access to multiple companies



  • ReliaQuest warns Akira ransomware often spreads via compromised assets inherited during mergers and acquisitions
  • Most infections stem from unpatched SonicWall SSL VPN appliances, exploited for lateral movement and encryption
  • SonicWall recently patched CVE-2025-40601, a high-severity buffer overflow flaw affecting Gen7 and Gen8 firewalls

Companies buy and sell other companies all the time, but besides the clients, earnings, a different market, or talented staff, buyers often get something unexpected with their acquisition, too – a ransomware infection.

Cybersecurity researchers ReliaQuest recently published a new report about how Akira ransomware infects its victims, noting in every attack it analyzed between June and October 2025, the company was infected through an asset it had previously acquired, that already had compromised hardware in its network.


https://cdn.mos.cms.futurecdn.net/mX3W9KraGSUsScvjwiRudM-627-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img