Menu
Browse

Cyber Incident Victim: TeamViewer GmbH

Date:

Jun 2024

Location:

Summary

TeamViewer confirmed a cyberattack limited to its internal corporate IT environment, with no compromise of its product environment, connectivity platform, or customer data. Attackers exploited a compromised standard employee account to copy information from the employee directory, including names, business contact details, and encrypted passwords for internal systems. The company attributed the incident to APT29/Midnight Blizzard and implemented enhanced authentication protocols, additional security safeguards, and initiated a complete rebuild of its corporate IT infrastructure. Response efforts involved collaboration with Microsoft's incident response team, cybersecurity experts, and authorities, while maintaining strict separation between corporate and product environments under its defense-in-depth architecture.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On June 26, 2024, TeamViewer’s security team detected anomalous activity within its internal corporate IT environment. The company immediately activated its incident response protocols, engaging external cybersecurity experts and initiating a forensic investigation. Preliminary findings indicated the attack originated from a compromised standard employee account accessed on June 26, with suspicious behavior identified through continuous security monitoring. TeamViewer’s task force, collaborating with global cybersecurity specialists and threat intelligence providers, attributed the intrusion to the advanced persistent threat group APT29/Midnight Blizzard. The investigation confirmed the attackers copied data from TeamViewer’s employee directory, including employee names, business contact details, and encrypted passwords specific to the corporate IT infrastructure. No evidence suggested lateral movement into TeamViewer’s product environment, connectivity platform, or customer data repositories, a containment attributed to the organization’s strict architectural segregation between corporate, product, and connectivity systems.

Cyber Incident Image

TeamViewer implemented immediate countermeasures, including enhanced authentication protocols for employee accounts and additional security controls to mitigate risks associated with the exfiltrated encrypted passwords. The company partnered with Microsoft’s incident response team to reinforce these actions and initiated a comprehensive rebuild of its corporate IT environment. Authorities and affected employees were notified, with ongoing updates provided through TeamViewer’s Trust Center. The investigation remained active, with no further compromises detected beyond the initial corporate IT breach. TeamViewer reiterated its commitment to transparency and security, emphasizing its defense-in-depth strategy and the structural isolation of critical systems as pivotal factors in limiting the incident’s scope.

Sources
Sources available to members
1 source