TeamViewer's corporate network was breached by APT29
- Organization
- TeamViewer
- Exploit
- Credential Compromise
- Industry
- Software
TeamViewer, the German remote access and remote management software vendor, said its security team detected an irregularity in the company's internal corporate information technology environment on June 26, 2024. It issued a first public statement the following day and activated its incident response process alongside outside specialists, including Microsoft's incident response team.
The company attributed the intrusion to APT29, the Russian state-linked group also tracked as Midnight Blizzard, Cozy Bear and Nobelium. Access was traced to the compromised credentials of a standard employee account within the corporate environment.
TeamViewer said the attacker copied employee directory data, specifically names, corporate contact information and encrypted employee passwords. It found no evidence that anything beyond the corporate environment had been reached and stated that neither its separated product environment, nor its connectivity platform, nor any customer data had been touched. The company credited the segregation between corporate IT, production systems and the connectivity platform with containing the intrusion.
TeamViewer concluded its investigation in early July 2024. It said it had hardened employee authentication procedures, added further layers of protection and monitoring, and rebuilt the internal corporate IT environment to return it to a fully trusted state.