THREAT BRIEFING · 12.08.2026 DEENFRES

Practice & Implementation

The Edge Device as a Ransomware Gateway: Why MFA at the VPN Is Not Enough

By Alec Chizhik · May 29, 2026 · 6 min read

7 Min. read time

The device meant to shield a network from external threats has become the most common entry point for ransomware. The Akira group compromised corporate networks en masse via unpatched SonicWall VPNs – often even where multi-factor authentication was enabled. The lesson is uncomfortable and relevant for every SOC in the DACH region: an appliance at the network edge isn’t a protective barrier, but a high-value attack target with its own patching obligations.

Key Takeaways

  • Edge devices are the gateway. VPN and firewall appliances sit at the start of most current ransomware attack chains.
  • MFA alone isn’t enough. Attackers breached networks even with multi-factor authentication active, via hijacked sessions.
  • Patch lag is the real vulnerability. Exploits often target flaws for which fixes already exist.

Related:When the security product itself is the vulnerability  /  Time-to-exploit drops to 24 to 48 hours

Why Edge Devices Are the Target

What is an edge device? An edge device sits at the boundary between your internal network and the internet: VPN gateways, firewalls, SSL-VPN appliances. It’s publicly accessible, runs 24/7, and holds deep network privileges. That combination makes it invaluable to attackers – and a critical weak spot for defenders.

From an attacker’s perspective, the logic is straightforward. An edge device is exposed by design – otherwise, no one could access it remotely. It occupies a privileged position, controlling traffic into your internal network. And it’s patched less frequently than servers because updating a gateway often means brief downtime for all remote users. If you’re looking for leverage, this is where you’ll find the most.

That’s exactly what the Akira group exploited. Through unpatched SonicWall SSL-VPNs, attackers gained access to corporate networks and deployed ransomware. In Q3 2025, Akira incidents surged by roughly 300% compared to the previous quarter – nearly all traced back to compromised edge VPN devices. This isn’t an outlier; it’s a pattern.

+300 %
Increase in Akira ransomware incidents in Q3 2025 compared to the previous quarter – nearly all originating from compromised edge VPN devices.
Source: Industry analyses of the Akira campaign, 2025

Why MFA Wasn’t the Goal – Just a Stop Along the Way

The most unsettling part of the reports: Even accounts with active multi-factor authentication were compromised. Attackers successfully logged in via SSL-VPN, including passing the one-time password check. The second factor wasn’t bypassed – it was served up on a platter. This happens when credentials and session tokens are stolen or when old passwords are carried over unchanged during device migration.

For teams that see MFA as a box ticked, this is a harsh reality check. MFA raises the bar – it doesn’t remove it. If you hand over that factor via phishing or a hijacked session, you’re facing the same open door as before. The answer isn’t to ditch MFA but to make it phishing-resistant and monitor logins at the edge instead of treating them as a green light.

Dangerous Assumptions

  • The firewall protects – it’s not a target
  • MFA enabled means access is secure
  • Edge patches can wait until the next maintenance window

Resilient Practices

  • Edge devices with their own rapid patch cycle
  • Phishing-resistant MFA instead of one-time passwords
  • Actively monitor logins at the gateway

What a SOC Actually Takes Away from This

The first step is an honest inventory of your edge devices. Which VPN and firewall appliances are exposed to the internet? What firmware versions are running? When was the last patch applied? Surprisingly often, this overview is missing because the gateway is treated as a given – and no one includes it in routine vulnerability management. If it’s not inventoried, it’s not patched.

The second step is the patch cycle itself. An edge device can’t afford a weeks-old vulnerability because the time-to-exploit for these appliances is now measured in hours, not days. This demands a dedicated, fast-track window for edge updates – separate from the leisurely server schedule. Those who wait are giving attackers exactly the time they need.

The third step addresses assumptions after a migration. The exploited SonicWall flaw hit hardest where local passwords were carried over unchanged during a generational upgrade. Every migration is a moment to reset credentials and review configurations. A compromised password is a backdoor no one intentionally left open – yet there it is.

The firewall at the network edge isn’t a guard post to relax behind. It’s the most exposed machine in the house – and deserves the strictest patch discipline.

The sum of these three steps is anything but flashy: inventory, fast patches, clean credentials. That very unremarkableness is the point. The Akira wave doesn’t rely on brilliant zero-days – it thrives on known vulnerabilities in devices that are updated too rarely. Treat your edge device like the critical server it already is, and you cut off the most common ransomware chain at its source.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Why are VPN and firewall appliances such popular targets?

They’re exposed to the internet, run continuously, and have privileged access to the internal network. At the same time, they’re patched less frequently than servers because updates mean downtime for remote users. This combination makes them the most lucrative entry point.

How did attackers penetrate despite active MFA?

The second factor wasn’t bypassed – it was served up on a platter. Using stolen credentials and session tokens, or passwords carried over unchanged during a migration, attackers logged in through the front door, complete with a successfully entered one-time passcode.

What’s the most critical immediate action?

Start with a full inventory of all externally accessible edge devices and their firmware versions, followed by a rapid patch of known vulnerabilities. Most exploited flaws already have available updates.

Is enabling MFA enough?

No. MFA raises the bar but doesn’t eliminate the threat. Phishing-resistant MFA – rather than traditional one-time passwords – paired with gateway login monitoring makes more sense.

Why is migration a high-risk moment?

During generational transitions, configurations and accounts are often migrated as-is. If old passwords remain unchanged, they create a backdoor. Every migration should include a reset of credentials and a thorough configuration review.

More from the MBF Media Network

cloudmagazinVMware Cloud Foundation 9.1: AI workloads and the sovereignty question in your own data centerMyBusinessFuture16 Decision-Makers, One AI Researcher: Why B2B Sales Need to Become More PreciseDigital ChiefsAgentic AI without an owner: Who is liable when the AI agent makes a mistake

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH