← TeamViewer

2016 TeamViewer — corporate network intrusion (Winnti); delayed disclosure to 2019

2016 Unknown records affected Share on X

Data compromised

Vendor stated no verified customer/product-database exfiltration; corporate LAN context

Technical writeup

TeamViewer publicly confirmed in 2019 that its internal corporate network was breached in 2016, with reporting tying the intrusion to Chinese APT–style actors deploying the Winnti backdoor. The firm maintained it found no evidence that customer data, the product environment, or source code was compromised, distinguishing the incident from contemporaneous consumer reports of remote takeovers that TeamViewer attributed to credential reuse and weak passwords. Rows document a confirmed vendor corporate-network compromise with contested downstream data impact.

Root cause

Targeted intrusion of corporate IT (per vendor late disclosure)

References