Threat Research

SonicWall Research Finds Professional Services Firms Overruled by Their Own Cybersecurity Gaps as Attackers Target the Sector’s Privileged Data

New Professional Services Protect Brief reveals 3 billion IPS events, the largest attack volume of any tracked industry, and ten ransomware families targeting privileged client data

MILPITAS, Calif. – August 12, 2026 – SonicWall today released its 2026 Professional Services Protect Brief, a vertical-specific companion to the SonicWall 2026 Cyber Protect Report, revealing that law firms, accountancies, consulting practices, engineering firms and managed service providers generated 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry SonicWall tracks, and that 460 organizations in the sector are actively detecting ransomware campaigns, the broadest exposure of any vertical.

Every year, attacks look more sophisticated. In most ways they are; AI has made them faster, cleaner, and harder to spot at a glance. But the underlying methods have not changed. Attackers are still walking through the same unlocked doors. In professional services, those doors are open by design. Client portals, document management platforms, billing systems and collaboration tools are built to be accessible, and that accessibility is also the vulnerability.

“Professional services holds the kind of data that carries built-in leverage,” said Michael Crean, SonicWall SVP of Managed Services. “Client records tied to active legal matters, financial transactions, privileged communications, and for MSPs, administrative credentials into dozens of other organizations’ networks. We're not talking about harmless background data. For the client, it represents massive financial, legal, and reputational risk. Attackers know this value, and the data bears that out.”

SonicWall’s Professional Services Protect Brief draws on data from SonicWall’s global network of more than one million security sensors to document the specific attack patterns, exploitation vectors and ransomware campaigns defining the professional services threat landscape in the first half of 2026.

Key Findings from the 2026 SonicWall Professional Services Protect Brief

  • Professional services generated 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry SonicWall tracks.
  • SIPVicious VoIP exploitation generated 332 million combined hits (signatures ranked #3 and #6 by volume) — a scale unique to this sector among all tracked industries.
  • Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
  • Ten active ransomware families operated simultaneously against the sector, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).
  • Apache Log4j2 (Log4Shell) generated 107 million hits, 2.5 years after public disclosure and emergency patching across the industry.
  • Directory traversal, malformed request probes and remote code execution signatures account for 72% of all IPS volume in the sector.

An MSP Breach Is Never Just One Breach

Professional services firms hold a category of data that is uniquely valuable: client records tied to active legal matters, financial transactions, privileged communications, and, in the case of MSPs, administrative credentials for the networks of dozens of client organizations. That leverage is what drives ransomware targeting in the sector, and the MSP dimension compounds it. An MSP breach potentially provides access to every client environment the MSP manages, and ransomware groups understand the arithmetic.

“An MSP breach is not one breach, it’s potential access to every client environment that MSP manages,” continued Crean. “Ryuk and Sodinokibi don’t show up in professional services by accident. They specifically target organizations that hold administrative access to other organizations, because one compromised credential can cascade into dozens of networks at once. That’s not spray-and-pray, that’s a calculated market decision.”

Zero Trust in Practice: A Legal Industry Case Study

XimpleIT, a Colorado-based MSP specializing in legal industry clients, deployed SonicWall Cloud Secure Edge across its law firm customer base after a client breach caused by an unpatched legacy VPN. By replacing broad network trust with application-level, continuously verified access, XimpleIT eliminated implicit trust and prevented lateral movement across client environments, precisely the architecture shift this brief recommends for a vertical built on privileged communications and client records.

“Having somebody, a real person, who checks in regularly, provides assistance implementing new solutions, and helps us win deals is a big differentiator,” said Juan Serna, Founder and IT Director, XimpleIT, a SonicWall partner. “That is rare. SonicWall gives us the platform and the partnership to walk into a law firm and tell them, with confidence, that their data is protected, not just monitored.”

To learn more, visit SonicWall at www.sonicwall.com.  

About SonicWall  
SonicWall is a partner-first unified cybersecurity portfolio that helps SMBs, MSPs, and IT teams consolidate network, endpoint, cloud, and threat response across hybrid environments. For more than 30 years, SonicWall has championed a partner-first model that combines purpose-built technology, cloud-delivered security services and real-time threat intelligence to help businesses prevent breaches, reduce risk and stay operational in the face of evolving modern threats. We are committed to deliver the best security outcomes for our customers where others deliver features and functions. Through its unified cybersecurity portfolio and global community of over 17,000 partners, SonicWall enables managed service providers to actively manage, continuously optimize and measurably protect networks, cloud environments, endpoints and applications. The company is redefining cybersecurity around outcomes that matter to business leaders, including breach prevention, compliance achievement, cost efficiency and reduced human error, because protection is not about what a product can do but about what it actually delivers. 

Latest Stories

  • SonicWall, MSP를 위한 차세대 네트워크 보안 솔루션으로 사이버 보안을 재정의하고 새로운 기준을 정립
    계층화된 보안, 공동 관리 서비스, 통합 관리 플랫폼으로 든든한 보안을 제공하는 SonicWall은 차세대 방화벽을 활용한 지속적인 혁신으로 파트너가 수익성 있는 서비스를 키울 수 있도록 돕고 있습니다.캘리포니아주 밀피타스 — 2025년 5월 5일 — SonicWall은 날로 늘어나는 오늘 관리형 서비스 제공자(MSP) 및 고객의 포괄적인 보호 및...
    Read More
  • SonicWall 위협 데이터로 드러난 사이버 공격의 깊이 - 높아지는 관리형 서비스 제공자(MSP)의 필요성
    총 침해 공격 건수 증가(+20%), 위협 행위자의 전술 다각화 - 전 세계에서 공격 증가 랜섬웨어는 한 해 내내 거셌으며(하반기 +27%) 여름철에 절정(+37%) 총 크립토재킹 공격 건수 – 전 세계에서 +659% 급증 IoT 취약점 공격(+15%)와 암호화된 위협(+117%)도 상승세 '기존에 없었던' 맬웨어 변종 SonicWall...
    Read More
  • SonicWall, 관리형 엔드포인트 보안서비스로 확대하고 있습니다,
    SonicWall은 파트너 성장을 더욱더 촉진하기 위해 연중무휴24x7 보안운영센터(SOC)를 갖춘 관리형 탐지 및 대응(MDR) 제품군을 새롭게 확장합니다. 캘리포니아주 밀피타스 — 2024년 2월 8일 —소중한 채널 파트너의 피드백을 반영하여 SonicWall은 오늘, MSP를 위해 맞춤 구성된 여러 관리형 서비스가 제공된다고 발표했습니다. SonicW...
    Read More