ConnectWise Hack: Nation-State Cyberattack Details
- ConnectWise, an IT management software company, has acknowledged a cyberattack impacting a limited number of its ScreenConnect customers.
- The florida-based firm, which offers remote monitoring and management (RMM), cybersecurity, and automation solutions, is working wiht Mandiant, a cybersecurity forensics expert, to investigate the incident.
- ConnectWise's ScreenConnect is a remote access tool used by technicians for troubleshooting and system maintenance.
ConnectWise confirms a damaging cyberattack impacting ScreenConnect customers, pointing to a sophisticated nation-state actor as the culprit. This breach, potentially linked to CVE-2025-3935, prompted immediate action; ConnectWise swiftly implemented enhanced security measures across its network to contain the damage. Reports indicate the remote access tool was targeted, but details remain limited regarding the scope and specific indicators of compromise. News directory 3 keeps you informed. Expect further updates as ConnectWise,with the aid of Mandiant,continues its investigation and collaborates with law enforcement. Discover what’s next for affected customers and potential future impacts.
ConnectWise Confirms ScreenConnect Cyberattack Linked to Nation-State Actor
updated May 30, 2025
ConnectWise, an IT management software company, has acknowledged a cyberattack impacting a limited number of its ScreenConnect customers. The company believes a sophisticated, state-sponsored actor was behind the breach.
The florida-based firm, which offers remote monitoring and management (RMM), cybersecurity, and automation solutions, is working wiht Mandiant, a cybersecurity forensics expert, to investigate the incident. Law enforcement has also been notified.
ConnectWise’s ScreenConnect is a remote access tool used by technicians for troubleshooting and system maintenance.
Following the incident, ConnectWise has implemented enhanced monitoring and strengthened security across its network. The company reports no further suspicious activity has been detected.
While ConnectWise has not released specific details regarding the number of affected customers or the timeline of the breach, a source indicated the initial breach occurred in August 2024, with suspicious activity detected in May 2025, impacting cloud-based ScreenConnect instances.
CNWR President Jason Slagle suggested the attack was targeted, affecting only a small number of customers.
The incident appears linked to CVE-2025-3935, a high-severity ViewState code injection vulnerability patched in April. This flaw could allow attackers with system-level access to steal secret machine keys and execute remote code.
ConnectWise had previously flagged the vulnerability as “High” priority and patched its cloud-hosted platforms before public disclosure.
Customers have expressed frustration over the limited details and lack of indicators of compromise (IOCs) provided by ConnectWise.
In the past, a ScreenConnect flaw, CVE-2024-1709, was exploited by ransomware groups and a North Korean APT for malware deployment.
Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.
What’s next
connectwise continues its investigation with Mandiant and is coordinating with law enforcement. The company is expected to release further details as the investigation progresses, providing affected customers with necessary information and support to mitigate potential risks associated with this ScreenConnect cyberattack.

