AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems. BleepingComputer has learned that data was stolen during the attack. AnyDesk is a remote access solution that allows users to remotely access computers over a network or the internet. The program is very popular with the enterprise, which use it for remote support or to access colocated servers. The software is also popular among threat actors who use it for persistent access to breached devices and networks. The company reports having 170,000 customers, including 7-Eleven, Comcast, Samsung, MIT, NVIDIA, SIEMENS, and the United Nations. In a statement shared with BleepingComputer, AnyDesk says they first learned of the attack after detecting indications of an incident on their product servers. After conducting a security audit, they determined their systems were compromised and activated a response plan with the help of cybersecurity firm CrowdStrike. AnyDesk says they have revoked security-related certificates and replaced systems as necessary. They also reassured customers that AnyDesk was safe to use and that there was no evidence of end-user devices being affected by the incident. While AnyDesk did not share too many details regarding what was stolen during the attack, BleepingComputer has learned that the threat actors accessed source code and code signing certificates. While the company says that no authentication tokens were stolen, ou...
AnyDesk says hackers breached its production servers, resets passwords
BleepingComputer
·Lawrence Abrams
·Published Feb 2, 2024
·Updated
Affected Software
1 affected component
AnyDesk Remote Access