ConnectWise has brought in the big guns to investigate a "sophisticated nation state actor" that broke into its IT environment and then breached some of its customers. In a May 28 advisory, the IT management software vendor said the compromise "affected a very small number" of its customers who use ScreenConnect, a remote access and management tool. Multiple major brands, including Panasonic, Swarovski, Aflac, and Honeywell, use this product, according to the software provider, so this type of supply-chain attack would not be good for business. The Register asked ConnectWise for more details about the breach, including how the intruders gained initial access to its systems, how many customers' instances they then broke into, and what they did — deploy ransomware? Steal data? We will update this story if we receive a response. In its May 28 alert, ConnectWise said it hired Google-owned cleanup crew Mandiant to investigate the security breach. "We have launched an investigation with one of the leading forensic experts, Mandiant," the advisory said. "We have contacted all affected customers and are coordinating with law enforcement." The vendor added that it has since boosted monitoring and hardened security across its environment, and has "not observed any further suspicious activity in any customer instances." One "pissed off" person claiming to be a ScreenConnect customer whose instance was compromised took to Reddit to vent. They said they received a "cryptic message" from a...
ConnectWise customers get mysterious warning about 'sophisticated' nation-state hack
The Register
·Jessica Lyons
·Published May 30, 2025
·Updated
Affected Software
3 affected components
ConnectWise ScreenConnect=25.2.4
ConnectWise ScreenConnect
ConnectWise ScreenConnect
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a sophisticated nation-state hack targeting ConnectWise and its customers.
2
What security implications are discussed?
The article highlights concerns about the breach of customer data and the capabilities of sophisticated nation-state actors.
3
What products or software are affected?
The affected software is ConnectWise ScreenConnect, specifically version 25.2.4.
4
What actions has ConnectWise taken following the breach?
ConnectWise has engaged advanced security experts to investigate the breach and its implications.
5
When was the advisory about the breach issued?
The advisory regarding the breach was issued on May 28.