• News/
  • https://www.theregister.com/2025/05/30/connectwise_compromised_by_sophisticated_government/

ConnectWise customers get mysterious warning about 'sophisticated' nation-state hack

The Register
·
Jessica Lyons
·
Published May 30, 2025
·
Updated

ConnectWise has brought in the big guns to investigate a "sophisticated nation state actor" that broke into its IT environment and then breached some of its customers. In a May 28 advisory, the IT management software vendor said the compromise "affected a very small number" of its customers who use ScreenConnect, a remote access and management tool. Multiple major brands, including Panasonic, Swarovski, Aflac, and Honeywell, use this product, according to the software provider, so this type of supply-chain attack would not be good for business. The Register asked ConnectWise for more details about the breach, including how the intruders gained initial access to its systems, how many customers' instances they then broke into, and what they did — deploy ransomware? Steal data? We will update this story if we receive a response. In its May 28 alert, ConnectWise said it hired Google-owned cleanup crew Mandiant to investigate the security breach. "We have launched an investigation with one of the leading forensic experts, Mandiant," the advisory said. "We have contacted all affected customers and are coordinating with law enforcement." The vendor added that it has since boosted monitoring and hardened security across its environment, and has "not observed any further suspicious activity in any customer instances." One "pissed off" person claiming to be a ScreenConnect customer whose instance was compromised took to Reddit to vent. They said they received a "cryptic message" from a...

Read full article

Affected Software

3 affected components
ConnectWise ScreenConnect=25.2.4
ConnectWise ScreenConnect
ConnectWise ScreenConnect
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a sophisticated nation-state hack targeting ConnectWise and its customers.

2

What security implications are discussed?

The article highlights concerns about the breach of customer data and the capabilities of sophisticated nation-state actors.

3

What products or software are affected?

The affected software is ConnectWise ScreenConnect, specifically version 25.2.4.

4

What actions has ConnectWise taken following the breach?

ConnectWise has engaged advanced security experts to investigate the breach and its implications.

5

When was the advisory about the breach issued?

The advisory regarding the breach was issued on May 28.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203