INC Ransomware has established itself as the primary threat actor targeting vulnerabilities within SonicWall Secure Mobile Access (SMA) 1000 appliances, according to Security Affairs. The group is leveraging two specific security flaws, identified as CVE-2026-15409 and CVE-2026-15410, to breach corporate networks across multiple countries, including the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.
Research indicates that while the exploitation activity began as early as June 2026, it intensified significantly starting in August. Attackers utilize compromised VPN gateways to obtain sensitive data, including session information, login credentials, and internal network maps. Once the network is compromised, the group engages in high-pressure extortion tactics, including direct phone calls and emails to organization representatives.
In one documented case, a caller identifying himself as "Andrew" contacted a target from the phone number +1 (304) 384-0401, claiming to represent a hacker collective. The caller directed the victim to negotiate through the email address info@helprans.com. The associated domain, helprans.com, was registered on June 2, 2026, through CNOBIN INFORMATION TECHNOLOGY LIMITED, utilizing a registrar that accepts cryptocurrency payments. Both vulnerabilities are now listed in the CISA Known Exploited Vulnerabilities Catalog, signaling their widespread use in active campaigns.
Technical Data Summary
| Data Point | Value |
|---|---|
| CVE Identifiers | CVE-2026-15409, CVE-2026-15410 |
| Domain Registration | June 2, 2026 |
| Registrar IANA ID | 3254 |
| Threat Caller Phone | +1 (304) 384-0401 |
| Contact Email | info@helprans.com |
| Expiration Date | June 2, 2027 |
Why It Matters
The transition toward multi-channel extortion—where threat actors combine technical network infiltration with direct, verbal intimidation—represents a shift in how ransomware groups manage post-breach leverage. By reaching out via telephone, attackers bypass automated security alerts and target human psychological triggers, increasing the likelihood of ransom payment. This tactic highlights the necessity for incident response teams to include crisis communications and executive security protocols, as the technical remediation of a VPN vulnerability is no longer the sole requirement for containing a live extortion attempt.
Reader Discussion & Insights