CSIDB logo
Incident

ConnectWise

Incident posture

Attack window
Nov 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-22 00:00

Linked entities

Victim
ConnectWise
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

ConnectWise faced ransomware attacks targeting on-premise installations of its Automate software, which enables centralized IT asset management. Attackers sought to compromise servers and deploy ransomware across entire customer networks, prompting the company to issue a security alert directing users to a support page for mitigation steps. However, the advisory lacked technical specifics such as exploited ports or attack vectors, leading to public confusion and reports of contradictory guidance in documentation. This incident followed prior ransomware campaigns against the platform, including one exploiting outdated plugins to distribute malware. The software is utilized by over 100,000 IT professionals, amplifying potential impacts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 8, 2019, ConnectWise alerted customers to active ransomware attacks targeting on-premise installations of its Automate software, a centralized IT management platform used to administer computer fleets and IT assets. Attackers sought to compromise these systems to gain control of servers and deploy ransomware across entire customer networks. The company emphasized that only on-premise deployments—chosen by organizations for heightened security—were affected, excluding its cloud-based offerings. ConnectWise issued mitigation guidance through a dedicated support page, urging users to implement unspecified security measures. However, the advisory omitted critical technical details regarding attacker methodologies, such as exploited vulnerabilities, network ports, or initial access vectors. This lack of specificity generated confusion among users, who publicly sought clarification on social media platforms like Twitter regarding precise attack mechanisms.

The incident represented a recurring threat pattern for ConnectWise, following a February 2019 attack where adversaries exploited an outdated plugin in Automate to distribute GandCrab ransomware. While the 2019 alert did not name the ransomware variant involved, it underscored the systemic risk posed by server compromises, enabling lateral movement and network-wide encryption. Contradictory instructions on the provided support page further complicated customer response efforts. With over 100,000 IT professionals relying on ConnectWise software, the attacks threatened widespread operational disruption through potential encryption of managed endpoints. The company’s notification focused exclusively on procedural countermeasures rather than disclosing forensic findings or indicators of compromise associated with the ongoing campaign.

Sources

Sources available to members: 1 source.

CSIDB