iTnews Asia
  • Home
  • News
  • Security

AnyDesk resets passwords after breach

AnyDesk resets passwords after breach

Some account credentials offered for sale.

By Richard Chirgwin on Feb 5, 2024 12:14PM

Remote access company AnyDesk has disclosed a breach of its systems and reset users’ passwords, with some user credentials allegedly leaked on dark web sites.

In a notice, the company also said it is revoking the code signing certificate used to sign its binaries, and will be issuing a new one.

This indicates that some source code may have been exfiltrated in the attack.

The password reset affects users of the company’s web portal, my.anydesk.com, and the company says users should reset passwords on any services they used the same credentials on.

AnyDesk said it took the action “following indications of an incident on some of our systems,” and that “a security audit … found evidence of compromised production systems.”

The organisation has notified authorities in the US and has called in CrowdStrike to help.

Resecurity said that on February 3, it “identified multiple threat actors selling access to compromised AnyDesk credentials on cybercriminal forums”, including one listing claiming to have 18,000 credentials for sale.

Resecurity noted that accounts listed for sale did not have MFA enabled.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
anydesk crowdstrike security

Related Articles

  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.