← TeamViewer

2024 TeamViewer — APT29 corporate IT intrusion (June); product stack asserted isolated

2024 Unknown records affected Share on X

Data compromised

Vendor characterization: internal corporate systems only; no customer telemetry exfiltration asserted

Technical writeup

TeamViewer reported that in late June 2024 a state-sponsored group widely associated with APT29 / Midnight Blizzard obtained access to its internal corporate IT environment using compromised employee credentials. The company’s security bulletin emphasized that the production product environment, customer connections, and customer data were segregated and not impacted, and that support and marketing systems were remediated. Independent coverage treated the incident as a second high-profile corporate-network breach narrative after the firm’s 2016 confirmation.

Root cause

APT-style intrusion via compromised workforce credentials against corporate IT

References