IT management software firm ConnectWise says a suspected state-sponsored cyberattack breached its environment and impacted a limited number of ScreenConnect customers. "ConnectWise recently learned of suspicious activity within our environment that we believe was tied to a sophisticated nation state actor, which affected a very small number of ScreenConnect customers," ConnectWise shared in a brief advisory. "We have launched an investigation with one of the leading forensic experts, Mandiant. We have contacted all affected customers and are coordinating with law enforcement." ConnectWise is a Florida-based software company that provides IT management, RMM (remote monitoring and management), cybersecurity, and automation solutions for managed service providers (MSPs) and IT departments. One of its products is ScreenConnect, a remote access and support tool that allows technicians to securely connect to client systems for troubleshooting, patching, and system maintenance. As first reported by CRN, the company now says it has implemented enhanced monitoring and hardened the security across its network. They also state that they have not seen any further suspicious activity in customer instances. ConnectWise did not answer BleepingComputer's questions about how many customers were impacted, when the breach occurred, or whether any malicious activity was observed in customers' ScreenConnect instances. However, a source told BleepingComputer that the breach occurred in August 202...
ConnectWise breached in cyberattack linked to nation-state hackers
BleepingComputer
·Lawrence Abrams
·Published May 29, 2025
·Updated
Affected Software
3 affected components
ConnectWise ScreenConnect=25.2.3
ConnectWise ScreenConnect
ConnectWise ScreenConnect
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a cybersecurity breach involving ConnectWise, attributed to nation-state hackers.
2
What security implications are discussed in the article?
The article highlights potential risks to customer data and the vulnerability of IT management systems to targeted cyberattacks.
3
What products or software are affected by the breach?
The breach specifically impacts the ConnectWise ScreenConnect software, version 25.2.3.
4
Was the breach widespread or limited in scope?
The article notes that the breach affected a limited number of ScreenConnect customers.
5
What response has ConnectWise taken regarding the cyberattack?
ConnectWise has acknowledged the breach and is investigating the suspicious activity to mitigate the impact.