On 15 July 2026, InternetNow’s SOC caught something during routine threat hunting: a distributed password-spraying campaign against Sophos Firewall VPN portals, using randomised usernames and rotating external IPs designed to slip under standard lockout thresholds.

Here’s the part that should worry every Sophos Firewall customer — this wasn’t isolated to one environment. The same signature turned up independently across a number of separate, unrelated customers we monitor. That’s not a coincidence. That’s a pattern. And based on what we’re seeing, we believe this campaign is likely affecting the large majority of organisations running Sophos Firewall — including many that haven’t spotted it yet in their own logs.

What we found:

A known, repeat-offender attack IP with 105 abuse reports from 19 independent sources, active as recently as three weeks ago

No successful logins recorded — but only because MFA held the line, not because the attempts stopped

Common first-response moves, like geo-blocking, that sound reassuring but don’t actually stop this specific attack

The full advisory breaks down exactly how the campaign works, why some of the obvious fixes fall short, and the specific, prioritised steps to close the gap — immediate actions, short-term mitigations, and the strategic call every Sophos Firewall customer needs to make.

If you’re running Sophos Firewall with an internet-facing VPN portal, this isn’t a “read when you get a chance” advisory. It’s a “check today” one.

Prepared by
InternetNow’s Security Operations Centre (Insightnow SOC)

Security_Finding_Password_Spray_Sophos_VPN