ConnectWise A.I CyberSecurity Scoring
ConnectWise
Company Information
Website:https://www.connectwise.com/
Employees number:3,409
Number of followers:223,791
NAICS:5112
Industry Type:Software Development
Homepage:connectwise.com
ConnectWise Risk Score (AI oriented)
Between 600 and 649
ConnectWiseSoftware Development
Updated:
17/07/2026
17/07/2026
628/1000
Poor
Caa
ConnectWise Global Score (TPRM)
xxxx
ConnectWiseSoftware Development
Score locked

ConnectWisePoor
Current Score
628Caa (POOR)
01000
11 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
630
JULY 2026
626
JUNE 2026
623
MAY 2026
618
APRIL 2026
614
MARCH 2026
615
Vulnerability
18 Mar 2026 • ConnectWise
ConnectWise: ScreenConnect Vulnerability Allows Hackers to Extract Unique Machine Keys and Hijack Sessions
Critical ScreenConnect Vulnerability Exposes Remote Desktop Sessions to Hijacking
611
CRITICAL-4
CON1773851361
Critical ScreenConnect Vulnerability Exposes Remote Desktop Sessions to Hijacking
ConnectWise has issued an urgent security advisory for its ScreenConnect remote desktop software, revealing a critical cryptographic flaw (CVE-2026-3564) that could enable unauthenticated attackers to extract server-level machine keys and bypass session authentication. The vulnerability, assigned a CVSS score of 9.0, affects all ScreenConnect versions prior to 26.1 and is classified as Priority 1 (High) due to active or imminent exploitation risks.
The flaw stems from plaintext storage of machine keys and cryptographic identifiers in server configuration files, allowing attackers with filesystem or configuration access to extract them without elevated privileges. Once obtained, these keys can be used to forge session tokens, impersonate legitimate users, and circumvent access controls. The issue is rooted in CWE-347 (Improper Verification of Cryptographic Signature), where the software fails to validate cryptographic integrity before trusting authentication components.
Exploitation requires no user interaction or privileges, though the attack complexity remains high due to specific conditions. The scope is marked as "Changed", meaning successful exploitation could impact resources beyond the vulnerable component a major concern for enterprises relying on ScreenConnect for remote access.
ConnectWise has released ScreenConnect 26.1, which mitigates the flaw by encrypting key storage and improving key management. Cloud-hosted instances are already protected, but on-premises deployments must manually upgrade to version 26.1, with lapsed maintenance licenses requiring renewal before patching. Security teams are advised to prioritize remediation and review session logs for signs of prior exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
632
Cyber Attack
01 Mar 2026 • ConnectWise
Bandicam, ScreenConnect and OBS Studio: How a single ScreenConnect incident exposed a massive campaign
Cybercriminals Exploit Legitimate Remote Access Tool in Large-Scale Malware Campaign
613
CRITICAL-19
BANOBSCON1782901541
Cybercriminals Exploit Legitimate Remote Access Tool in Large-Scale Malware Campaign
In a recent investigation, Kaspersky’s Managed Detection and Response (MDR) team uncovered a sophisticated cyberattack leveraging ScreenConnect, a legitimate remote monitoring tool, to deploy AsyncRAT malware. The campaign, active since October 2025, spans over 90 spoofed domains in 10 languages, targeting users worldwide through typosquatted websites impersonating popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.
### How the Attack Works
1. Initial Compromise
- Victims unknowingly download malicious installers from fraudulent websites ranking high in search engine results due to SEO manipulation.
- The downloaded archives (e.g., obs-studio-windows-x64.zip) contain a legitimate Microsoft-signed *install.exe alongside a malicious install.res.1033.dll* library.
- Upon execution, the DLL sideloads ScreenConnect, installing it silently via msiexec.exe under the guise of a "Microsoft Update Service."
2. Post-Exploitation Tactics
- ScreenConnect deploys PowerShell and VBS scripts to:
- Disable Microsoft Defender by excluding critical directories (C:\, C:\Users\Public).
- Turn off User Account Control (UAC) by modifying registry keys.
- Terminate running PowerShell processes to evade detection.
- A VBScript (*installer_method3_stream.vbs*) drops five files in C:\Users\Public, including secret_bytes.txt, which contains an XOR-encrypted AsyncRAT payload.
- The malware uses process hollowing to inject AsyncRAT into RegAsm.exe, a trusted Windows process, and establishes persistence via a scheduled task (*MasterPackager.Updater*) that re-executes every two minutes.
3. Command-and-Control (C2) Infrastructure
- AsyncRAT connects to mora1987[.]work[.]gd and other C2 domains.
- ScreenConnect’s C2 servers (e.g., r.servermanagemen[.]xyz) are embedded in system.config XML files within the MSI packages.
### Campaign Scale & Infrastructure
- Spoofed Websites: Over 90 domains mimic software vendors, hosted across three IP clusters (U.S. and Germany).
- Cluster 1 (162.216.241[.]242, 198.23.185[.]81): Initially used for gaming-themed lures, later shifted to freeware impersonation.
- Cluster 2 (2.59.134[.]97): Focused exclusively on fake software portals.
- Global Reach: Domains localized in English, Russian, Chinese, German, French, Spanish, and Arabic, indicating a broad targeting strategy.
- SEO Abuse: Fraudulent sites appear at the top of search results for queries like "OBS Studio download," increasing victim exposure.
### Impact & Objectives
- Targets: Both individual users and corporate networks, where remote access tools are often allowlisted.
- Goal: Likely credential theft and unauthorized system access, with compromised endpoints potentially resold on dark web marketplaces.
- Persistence: The attack chain ensures long-term control over infected devices via ScreenConnect and AsyncRAT.
### Detection & Indicators
Kaspersky’s MDR detected the attack through:
- ScreenConnect service creation with suspicious parameters.
- Anomalous child processes (e.g., powershell.exe, schtasks.exe) spawned by ScreenConnect.
- Malware signatures (e.g., Trojan.Win64.DLLhijack., Trojan.VBS.Agent.).
Key IOCs:
- Malicious DLL: install.res.1033.dll (MD5: 5F96C04E3AFAE97017B201BE112284D2).
- C2 Domains: mora1987[.]work[.]gd, servermanagemen[.]xyz.
- Fake Websites: studioobs[.]com, dnsjumper[.]app, ds4windows[.]pro.
The campaign highlights the risks of trusted remote tools and typosquatting, underscoring the need for strict software controls and outbound traffic monitoring. Many fraudulent domains remain active as of publication.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
649
Cyber Attack
10 Feb 2026 • ConnectWise
ConnectWise, Datto, SmartVault, SimpleHelp and Amazon: Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
Microsoft Warns of Tax-Season Phishing Surge Targeting U.S. Organizations
630
CRITICAL-19
SMASIMCONAMADAT1775551328
Microsoft Warns of Tax-Season Phishing Surge Targeting U.S. Organizations
Microsoft has identified a wave of phishing campaigns exploiting the U.S. tax season to steal credentials and deploy malware. Threat actors are leveraging urgent, time-sensitive lures such as fake refund notices, payroll forms, and IRS impersonations to trick recipients into interacting with malicious links, QR codes, or attachments.
The attacks disproportionately target accountants, tax professionals, and industries handling sensitive financial data, including manufacturing, retail, healthcare, and higher education. Some campaigns use Phishing-as-a-Service (PhaaS) platforms like Energy365 and SneakyLog (Kratos) to harvest credentials, including two-factor authentication (2FA) codes, via spoofed Microsoft 365 login pages. Others deploy remote monitoring and management (RMM) tools such as ConnectWise ScreenConnect, Datto, and SimpleHelp to gain persistent access to compromised systems.
Key campaigns include:
- CPA-themed phishing using the Energy365 kit, sending hundreds of thousands of malicious emails daily.
- QR code and W-2 lures targeting ~100 U.S. organizations in manufacturing, retail, and healthcare, redirecting victims to fake Microsoft 365 sign-in pages.
- IRS impersonation with cryptocurrency tax form scams, distributing ScreenConnect or SimpleHelp via domains like irs-doc[.]com.
- Datto malware delivery via fake tax-filing assistance links sent to accountants.
- A large-scale February 10, 2026, attack affecting 29,000 users across 10,000 organizations, primarily in financial services, tech, and retail. Emails, sent via Amazon SES, claimed irregular tax returns under recipients’ Electronic Filing Identification Numbers (EFINs) and directed users to a fake SmartVault site (smartvault[.]im) to download a malicious ScreenConnect installer.
The campaigns highlight a 277% year-over-year surge in RMM tool abuse, with attackers daisy-chaining multiple tools to evade detection. Since RMM software is often trusted in corporate environments, unauthorized usage can go unnoticed, complicating attribution and response efforts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
707
Cyber Attack
01 Jan 2026 • ConnectWise
ConnectWise, LogMeIn, Kaseya, O&O Software, WebEx, Arctic Wolf, Oracle and Google: ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026
645
HIGH-62
ARCCONO&OLOGKASORAWEBGOO1784262481
Cybersecurity Roundup: Major Threats and Disruptions in Early 2026
A series of high-profile cyber threats and law enforcement actions have marked the first half of 2026, targeting individuals, businesses, and critical infrastructure across multiple regions.
### Phishing Campaigns Exploit RMM Tools and AI-Generated Lures
A sustained phishing operation, SeasonalInvite, has been active since January 2026, abusing commercial Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya, and O&O Syspectr to compromise Windows and macOS users. The campaign leverages seasonal themes, distributing malicious links via phishing emails and poisoned search results. Researchers identified 959 eCard-themed domains and a traffic distribution system (TDS) using 2,658 gate pages to evade security scanners. The phishing pages appear to be AI-generated, suggesting threat actors used large language models (LLMs) to rapidly adapt their tactics.
### Chrome Sync Feature Abused for Surveillance
A legitimate Chrome feature designed for cross-device synchronization has been weaponized by stalkers and cybercriminals. By briefly accessing a victim’s device, attackers can add a controlled Google account and enable sync, allowing them to monitor browsing history, bookmarks, and saved passwords in real time. The method requires no malware, making detection difficult.
### Spanish Police Dismantle €140M Cybercrime Network
Authorities in Spain, in collaboration with international partners, disrupted a €140 million cybercrime operation involving fake investment platforms, CEO fraud, and adversary-in-the-middle (AitM) attacks. Four suspects were arrested two in Portugal, one in Spain, and one in Panama. The group used 800+ bank accounts and a network of "money mules" to launder funds, funneling stolen cryptocurrency through third-country accounts.
### UAT-11795 Deploys Starland RAT and WLDR Implant in U.S. and Europe
A Russian-speaking threat actor, UAT-11795, has been targeting users in the U.S. and Europe since June 2025 with a Python-based remote access trojan (RAT) called Starland and a PowerShell-based C2 implant (WLDR agent). The campaign uses trojanized installers for popular software like MobaXterm, WebEx, Zoom, and DBeaver, delivering payloads via ClickFix lures. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine, enabling stealthy data exfiltration and further payload deployment.
### Ransomware Attack Encrypts Network in Under 24 Hours
An unnamed ransomware group compromised an internet-facing IIS web server in June 2026, deploying a Rust-based ransomware strain dubbed Spirals within 24 hours. The attackers used an ASP.NET web shell for initial access, disabled endpoint security, dumped the Security Account Manager (SAM) hive, and spread laterally using PsExec. The ransom note threatened to publish stolen data after six days if demands were not met.
### Vidar Stealer and XMRig Miner Campaign Targets Global Victims
A financially motivated campaign detected in April 2026 delivers Vidar stealer (targeting browser credentials, cookies, and crypto wallets) and XMRig cryptocurrency miner via malvertising. The malware, distributed through cracked software lures, uses the Factory-v3 malware-as-a-service (MaaS) framework. Operators monetize stolen data on criminal markets while generating passive income from hijacked CPU cycles.
### Fake GitHub Repositories Spread Windows Infostealer
A Russian-speaking threat actor created 290+ fake GitHub repositories impersonating trusted vendors like Arctic Wolf to distribute a Windows infostealer with the same codebase as BoryptGrab-Lineage. The malware targets 41 cryptocurrency wallet paths and 19+ browsers, exfiltrating stolen data to a Russian-hosted C2 server. The campaign highlights the risks of brandjacking and supply chain attacks.
### Dutch Authorities Arrest Alleged Mastermind Behind 700-Person Scam Network
A 46-year-old man with Israeli and Polish citizenship was arrested in the Netherlands for allegedly running a global investment fraud network employing 700+ scammers across 20 call centers. Victims were manipulated into depositing funds often in cryptocurrency into fake platforms, with scammers maintaining contact for months to build trust. The operation is linked to €140 million in losses.
### New Phishing Toolkits and MFA Bypass Techniques Emerge
- Jalisco: An AI-powered device code phishing toolkit that provisions fresh OAuth codes in real time, bypassing time-based MFA defenses.
- OmegaLord: A JavaScript-based credential harvester that impersonates a PDF reader and collects phone numbers alongside passwords to intercept MFA codes.
### U.S. and Allies Sanction Russian Cybercrime Groups
The U.S., U.K., and Australia imposed sanctions in November 2025 on Media Land LLC, ML.Cloud LLC, and three Russian nationals Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova for cybercrimes causing $62+ million in losses. The Rewards for Justice (RFJ) program offers up to $10 million for information on their activities.
### Critical Vulnerabilities Added to CISA’s KEV Catalog
CISA added two high-severity flaws to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-46817: An improper privilege management vulnerability in Oracle E-Business Suite.
- KNX Protocol Connection Authorization Option 1: An overly restrictive account lockout mechanism with unknown exploitation details.
### Eastern European C2 Infrastructure Mapped
A Hunt.io analysis uncovered 3,900+ threat-activity-enabling servers across 302 Eastern European providers, with Russia’s Media Land leading (1,277 IPs), followed by Tactical RMM (232) and Acunetix (173). The findings underscore the region’s role in hosting cybercriminal infrastructure.
### Malicious NuGet Packages Drop Surveillance Payloads
Eleven malicious NuGet packages, masquerading as game utilities and productivity tools, were found delivering a Python-based infostealer ("pepesoft.exe") from GitHub and Hugging Face. The payload uses AWS-style key material for remote configuration, binds activations to hardware, and includes a BitTorrent fallback mechanism.
### Windows Bind Links Exploited to Bypass EDR
Bitdefender researchers demonstrated three techniques File-Binding, Process-Binding, and Silo-Binding that abuse Windows’ bind links to evade EDR detection. While Microsoft rated the findings as low severity (requiring admin access), the methods highlight potential gaps in endpoint security.
### Key Takeaways
- Phishing and RMM abuse remain dominant attack vectors, with AI-generated lures increasing in sophistication.
- MFA bypass techniques (e.g., device code phishing, OAuth abuse) are evolving, reducing the effectiveness of traditional defenses.
- Ransomware and infostealers continue to target businesses and individuals, with 24-hour encryption timelines becoming more common.
- Law enforcement actions have disrupted major cybercrime networks, but threat actors rapidly adapt.
- Supply chain risks persist, with fake repositories and trojanized software posing significant threats.
The first half of 2026 has seen a surge in financially motivated cybercrime, state-linked activity, and novel evasion techniques, underscoring the need for robust detection and response strategies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Cyber Attack
01 Jan 2026 • ConnectWise
ScreenConnect: New Infostealer Dubbed ‘Pheno’ Hijacks Windows’ Phone Link App to Steal MFA OTPs
Cybercriminals Exploit Microsoft Phone Link to Steal SMS-Based OTPs Without Malware on Mobile Devices
645
CRITICAL-62
CON1778005541
Cybercriminals Exploit Microsoft Phone Link to Steal SMS-Based OTPs Without Malware on Mobile Devices
A sophisticated cyberattack campaign, active since at least January 2026, has uncovered a novel method to intercept SMS-based one-time passwords (OTPs) by targeting Windows PCs synced with mobile devices without deploying malware on the phones themselves. Researchers identified the attack leveraging a remote access trojan (RAT) called CloudZ, paired with a previously unknown plugin dubbed Pheno, to harvest credentials and authentication codes.
The attack exploits Microsoft Phone Link (formerly "Your Phone"), a built-in Windows 10 and 11 application that mirrors calls, messages, and app notifications from Android or iOS devices to a desktop. Pheno scans for active phone connections by detecting processes like PhoneExperienceHost or Link to Windows, then accesses the app’s local SQLite database where SMS messages and OTPs are stored bypassing mobile security controls entirely.
Unlike traditional attacks, this method avoids direct compromise of the mobile device, instead targeting the enterprise-managed Windows endpoint the phone trusts. The campaign highlights a critical gap in security strategies that prioritize smartphone protection over the desktop environments they sync with.
CloudZ, a modular .NET RAT compiled on January 13 and obfuscated with ConfuserEx, extends beyond Pheno’s OTP theft. It supports credential harvesting from browsers, file operations, remote command execution, and host profiling. The malware establishes an encrypted TCP connection to its command-and-control (C2) server, using rotating user-agent strings to blend with legitimate traffic. To evade detection, CloudZ dynamically generates executable functions in memory, avoiding static binary storage on disk, and checks for analysis tools like Wireshark, Fiddler, and Sysmon before execution.
The infection chain begins with a fake ScreenConnect update, a legitimate remote support tool widely used in enterprises. The malicious update deploys a Rust-compiled loader, which installs a .NET loader to deliver CloudZ and establish persistence via a scheduled task. Despite thorough analysis by Cisco Talos researchers, the threat actor behind the campaign remains unidentified, and the initial access vector is still unclear.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
707
NOVEMBER 2025
705
OCTOBER 2025
704
SEPTEMBER 2025
702
JUNE 2025
699
Vulnerability
04 Jun 2025 • ConnectWise
ConnectWise
Ongoing Intrusions Exploiting ConnectWise ScreenConnect Vulnerability (CVE-2025-3935) and Related KEV Additions by CISA
695
CRITICAL-4
CON2251822112925
The Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about active exploitation of CVE-2025-3935, a critical ConnectWise ScreenConnect vulnerability enabling ViewState code injection attacks. While suspected to be leveraged in a state-backed cyber intrusion, ConnectWise acknowledged only a limited number of affected customers, avoiding confirmation of the attack’s origin. The flaw allows unauthorized remote code execution, potentially granting attackers full system control, data exfiltration, or lateral movement within compromised networks. Though no large-scale data breaches or operational disruptions were publicly confirmed, the vulnerability’s exploitation poses severe risks—including unauthorized access to sensitive corporate or client data, disruption of remote monitoring/management services, or deployment of secondary payloads (e.g., ransomware or spyware). CISA’s inclusion of the flaw in its Known Exploited Vulnerabilities (KEV) catalog underscores its criticality, mandating urgent patching by June 23. The incident highlights the persistent threat of nation-state actors targeting widely used enterprise software to infiltrate supply chains, with potential cascading effects on dependent organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MAY 2025
718
Cyber Attack
29 May 2025 • ConnectWise
ConnectWise
Compromise of ConnectWise ScreenConnect Cloud Infrastructure in Suspected State-Sponsored Cyberattack
699
HIGH-19
CON2965729112825
ConnectWise, a Florida-based IT management software provider, experienced a cybersecurity incident involving the compromise of its ScreenConnect cloud infrastructure, suspected to be a state-sponsored cyberattack. The breach was contained swiftly through immediate patching, enhanced monitoring, and strengthened security mechanisms. While the exact scope of the data compromise remains undisclosed, the incident was limited to a small subset of organizations using ScreenConnect. Malicious activity was mitigated, and no further exploitation was reported. The event underscored vulnerabilities in managed service providers (MSPs), prompting industry calls for heightened security measures to protect vendors, MSPs, and end-users. No evidence suggested large-scale data theft, financial fraud, or operational disruptions beyond the initial intrusion. The focus remained on preventing future exploits rather than addressing widespread damage.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JANUARY 2025
716
Vulnerability
01 Jan 2025 • ConnectWise
Ivanti, PaperCut, ConnectWise and Microsoft: Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days to launch ransomware at targets across the world
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits
712
CRITICAL-4
CONMICPAPIVA1775607925
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits
A Chinese-speaking cybercriminal group, Storm-1175, is accelerating its attacks, moving from initial access to full system compromise including Medusa ransomware deployment in as little as 24 hours, according to a new Microsoft report. Unlike state-sponsored actors, the group operates for financial gain, targeting healthcare, finance, education, and professional services sectors, primarily in the U.S., U.K., and Australia.
Storm-1175 exploits a mix of zero-day and n-day vulnerabilities, often chaining flaws for maximum impact. The group has been observed abusing zero-days before public disclosure and rapidly weaponizing n-days leaving defenders minimal time to patch. Over 16 vulnerabilities across 10 products have been leveraged, including critical flaws in:
- Microsoft Exchange (CVE-2023-21529)
- PaperCut (CVE-2023-27351, CVE-2023-27350)
- Ivanti Connect Secure/Policy Secure (CVE-2023-46805, CVE-2024-21887)
- ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708)
- JetBrains TeamCity, SimpleHelp, CrushFTP, SmarterMail, and BeyondTrust
After gaining access, the group disables antivirus and endpoint protection, deploys tools for lateral movement and persistence, and exfiltrates data before encrypting systems with Medusa ransomware. Their high operational tempo and ability to identify exposed assets have made their attacks particularly effective.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
AUGUST 2024
729
Cyber Attack
01 Aug 2024 • ConnectWise
ConnectWise
Suspected State-Sponsored Cyberattack on ConnectWise's ScreenConnect
710
CRITICAL-19
CON454052925
ConnectWise, a Florida-based software company providing IT management solutions, experienced a suspected state-sponsored cyberattack that breached its environment. The attack impacted a limited number of ScreenConnect customers, a remote access and support tool. The breach occurred in August 2024 and was discovered in May 2025, with the vulnerability tracked as CVE-2025-3935. The flaw allowed threat actors with privileged access to steal secret machine keys and conduct remote code execution on ScreenConnect servers, potentially accessing customer environments. The company has implemented enhanced monitoring and security measures but has not confirmed the extent of the breach or the specifics of the malicious activity observed.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
DECEMBER 2022
712
Vulnerability
01 Dec 2022 • ConnectWise
ConnectWise
Phishing Attack on ConnectWise
707
CRITICAL-5
CON01841222
ConnectWise, which offers a self-hosted, remote desktop software application suffered an unusually sophisticated phishing attack that can let attackers take remote control over user systems when recipients click the included link.
The warning comes just weeks after the company quietly patched a vulnerability that makes it easier for phishers to launch these attacks.
In October, ConnectWise learned that an attacker could craft a ConnectWise Control client download link that would bounce or proxy the remote connection from the MSP’s servers to a server that the attacker controls.
ConnectWise issued advisory warning users to be on guard against a new round email phishing attempts that mimic legitimate email alerts the company sends when it detects unusual activity on a customer account.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JUNE 2020
769
Ransomware
01 Jun 2020 • ConnectWise
ConnectWise
Ransomware Attacks on ConnectWise Partners
666
CRITICAL-103
CON1166123
Multiple ConnectWise partners have had their customers hit with a ransomware attacks.
It was through a software flaw that left several end users compromised.
There was an MSP encrypted which is what prompted the company to release the hotfix and notify users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ConnectWise ??
What was ConnectWise's A.I Rankiteo Cyber Score in July 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in June 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in May 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in April 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in March 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in February 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in January 2026 ??
What was ConnectWise's A.I Rankiteo Cyber Score in December 2025 ??
What was ConnectWise's A.I Rankiteo Cyber Score in November 2025 ??
What was ConnectWise's A.I Rankiteo Cyber Score in October 2025 ??
What was ConnectWise's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on ConnectWise's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ConnectWise ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ConnectWise's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?