We have one site where they use a Verizon 4g connect (and pay per GB for overage.).
They contacted us last week and said they had received a bill for $6,000 in overage charges.
We worked with their provider last week who said that their 4G modem was compromised with malware. We RMA'd that, and figured the problem was resolved. ...Until they reported that 50GB of traffic was used the following day.
This is a small site - a couple computers. Traffic analytics shows nothing - like a few GB over a month. It is extremely inactive.
We worked with the ISP to get a packet capture from their layer 2 device... This revealed around 15 MB of traffic over a 5 min period - all going to one of Meraki's management IP's.
This is extremely abnormal, and very sketchy. Has anyone else seen anything like this?
I do have a case open that was sent over to engineering for me. I have a bad feeling about cases that get sent to the black hole of engineering.