2025 ConnectWise ScreenConnect — nation-state–linked exploitation (CVE-2025-3935); limited customers
Data compromised
Not publicly itemized; unauthorized RMM session access to affected customer servers
Technical writeup
ConnectWise disclosed suspicious activity in May 2025 attributed to a sophisticated nation-state actor affecting a small set of on-prem ScreenConnect customers, with Mandiant assisting forensics. Vendor and press tied malicious behavior to exploitation of CVE-2025-3935 (ViewState injection class issue) patched in ScreenConnect 25.2.4. Reporting characterized the operation as intelligence-focused with no broad ransomware deployment and no firm public quantification of data theft, though enterprise tenants experienced unauthorized remote-management access during the window.
Root cause
Targeted exploitation of patched remote-access software flaw against select deployments