Ransomware hackers attack SMBs that are acquired to try to gain access to more businesses


  • ReliaQuest warns that Akira ransomware is often spread via compromised assets inherited during mergers and acquisitions
  • Most infections originate from unpatched SonicWall SSL VPN appliances, exploited for lateral movement and encryption
  • SonicWall recently patched CVE-2025-40601, a high severity buffer overflow vulnerability affecting Gen7 and Gen8 firewalls

Companies buy and sell other companies all the time, but in addition to the customers, earnings, another market or talented employees, buyers often also get something unexpected with their acquisition – a ransomware infection.

Cybersecurity researchers ReliaQuest recently published a new report on how Akira ransomware infects its victims, noting that in every attack it analyzed between June and October 2025, the company was infected through an asset it had previously acquired that had already compromised hardware in its network.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top