AnyDesk resets passwords after breach

By

Some account credentials offered for sale.

Remote access company AnyDesk has disclosed a breach of its systems and reset users’ passwords, with some user credentials allegedly leaked on dark web sites.

AnyDesk resets passwords after breach

In a notice, the company also said it is revoking the code signing certificate used to sign its binaries, and will be issuing a new one.

This indicates that some source code may have been exfiltrated in the attack.

The password reset affects users of the company’s web portal, my.anydesk.com, and the company says users should reset passwords on any services they used the same credentials on.

AnyDesk said it took the action “following indications of an incident on some of our systems,” and that “a security audit … found evidence of compromised production systems.”

The organisation has notified authorities in the US and has called in CrowdStrike to help.

Resecurity said that on February 3, it “identified multiple threat actors selling access to compromised AnyDesk credentials on cybercriminal forums”, including one listing claiming to have 18,000 credentials for sale.

Resecurity noted that accounts listed for sale did not have MFA enabled.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

Log In

  |  Forgot your password?