TeamViewer , which provides popular remote access software , is warning that its corporate environment has been compromised . Some experts say an APT hacking group is behind the cyberattack .

“On Wednesday, June 26, 2024, our security team detected an irregularity in TeamViewer’s internal corporate IT environment,” TeamViewer said in a post. “We immediately activated the response team and related processes, launched investigations together with a team of cyber , and implemented the necessary remediation measures.”
TeamViewer clarified that its internal corporate IT environment is completely independent of the product environment. “There is no evidence to suggest that the product environment or customer data is affected,” the company said.
See also: Hacker says he breached India's eMigrate portal
Investigations continue with an emphasis on ensuring the integrity of the systems.
The company said it wants to be transparent and will provide ongoing updates on the incident.
TeamViewer is a very popular remote access software that allows users to remotely control a computer. The company says its product is currently used by more than 640,000 customers worldwide. Since its launch, it has been installed on more than 2.5 billion devices.
While TeamViewer states that there is no evidence that its product environment or data customer, the massive use of the software at both the consumer and enterprise levels makes any breach a significant concern.
TeamViewer should take additional measures to protect its corporate environment and conduct a detailed analysis of logs and logs to identify the source of the attack and understand how the hackers entered the system.
In addition, it should proceed with immediate updating of security policies and access protocols, strengthening protection and control measures to prevent future attacks.
See also: Cloud Breach: Half of Organizations Have Been Attacked
Finally, it is also necessary to train staff on new security practices and procedures that must be followed in the event of suspicious activity, enhancing preparedness and response to cyberattacks.

APT hacking group behind TeamViewer breach?
News of the breach was first reported on Mastodon by security professional Jeffrey , who shared parts of a notice shared with the Dutch Digital Trust Center.
“The NCC Group Global Threat Intelligence team has been notified of a significant breach of the TeamViewer remote access and support platform by an APT group,” says an alert from security firm NCC Group.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: CoinStats: North Korean hackers breached 1,590 crypto wallets
An alert from Health-ISAC, a community for healthcare professionals who share information about cyber threats, also warned that TeamViewer services are reportedly being actively targeted by the Russian hacking group APT29, also known as Cozy Bear, NOBELIUM, and Midnight Blizzard.
“Health-ISAC recommends checking log files for any unusual remote desktop traffic“.
However, the Health-ISAC alert focuses more on targeting TeamViewer connections, so it is uncertain whether it is linked to the breach of the company's corporate environment.
Source: www.bleepingcomputer.com
