{"id":77302,"date":"2024-02-08T09:09:49","date_gmt":"2024-02-08T14:09:49","guid":{"rendered":"https:\/\/blog.cyberconservices.com\/?p=77302"},"modified":"2024-02-08T09:09:49","modified_gmt":"2024-02-08T14:09:49","slug":"18000-user-credentials-offered-on-dark-web-after-anydesk-confirms-incident","status":"publish","type":"post","link":"https:\/\/blog.cyberconservices.com\/index.php\/2024\/02\/08\/18000-user-credentials-offered-on-dark-web-after-anydesk-confirms-incident\/","title":{"rendered":"18,000 User Credentials Offered on Dark Web After AnyDesk Confirms Incident"},"content":{"rendered":"<p>Last week, AnyDesk confirmed it was breached in a cyber-attack that wasn\u2019t a ransomware incident. The hackers compromised the remote desktop-sharing software provider\u2019s production systems. They could also access the source code and private code signing keys, according to Bleeping Computer.<\/p>\n<p>AnyDesk said it discovered the breach during a security audit, has revoked passwords for all users on my.anydesk.com, and is urging users to change similar reused passwords on other platforms.<\/p>\n<p>The action indicates hackers successfully getting their hands on sensitive information. However, it is unclear how easily they can crack it open since AnyDesk said their \u201csystems are designed not to store private keys, security tokens or passwords that could be exploited to connect to end-user devices.\u201d<\/p>\n<p>The necessity of the mitigation effort by revoking passwords is evident from cybersecurity company Resecurity discovering 18,317 AnyDesk customer credentials going up on sale on dark web forum exploit dot in. \u201cThis data is ideal for technical support scams and mailing (phishing),\u201d the seller wrote to Resecurity and asked for $15,000 in cryptocurrency for the data.<\/p>\n<p>The breach could also potentially expose AnyDesk customers\u2019 license keys, number of active connections, duration of sessions, customer ID and contact information, email associated with the account, and the total number of hosts that have remote access management software activated.<\/p>\n<p>\u201cBy targeting code signing certificates, it\u2019s likely that attackers were attempting to perform a one-to-many attack \u2013 i.e. using AnyDesk as a conduit to infect their customers and partners. Code signing certificates are very powerful machine identities \u2013 if a piece of software is signed with a valid identity of this kind, then it tells other machines it can be trusted, so an attacker can send out malware which automatically runs as safe. It essentially gives the bad guys a key to walk through the front door,\u201d Kevin Bocek, VP of Ecosystem and Community at Venafi, told Spiceworks.\u00a0\u00a0<a href=\"https:\/\/www.spiceworks.com\/it-security\/data-security\/news\/anydesk-server-breach\/?utm_source=swemail&amp;utm_medium=email&amp;utm_campaign=newsinsights+tech+461905&amp;utme=article1+button&amp;dm_i=78Z3,9WEP,28Y1FR,1F3QY,1\" target=\"_blank\" rel=\"noopener\">Read On:<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week, AnyDesk confirmed it was breached in a cyber-attack that wasn\u2019t a ransomware incident. The hackers compromised the remote desktop-sharing software provider\u2019s production systems. They could also access the source code and private code signing keys, according to Bleeping <span class=\"excerpt-dots\">&hellip;<\/span> <a class=\"more-link\" href=\"https:\/\/blog.cyberconservices.com\/index.php\/2024\/02\/08\/18000-user-credentials-offered-on-dark-web-after-anydesk-confirms-incident\/\"><span class=\"more-msg\">Continue reading &rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":77306,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1275,636,14],"tags":[1276,637,150],"class_list":["post-77302","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hack","category-ransomware","category-security","tag-hack","tag-ransomware","tag-security"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2024\/02\/High-resolution-image-of-a-computer-2.png?fit=1024%2C1024&ssl=1","jetpack-related-posts":[{"id":31890,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2019\/09\/19\/4-ways-hackers-use-phishing-to-launch-ransomware-attacks\/","url_meta":{"origin":77302,"position":0},"title":"4 Ways Hackers Use Phishing to Launch Ransomware Attacks","author":"Rick Backus","date":"September 19, 2019","format":false,"excerpt":"MSPs have been on the receiving end of relentless ransomware attacks in 2019. In June, hackers infiltrated a number of MSPs via their Webroot management consoles. What followed was an\u00a0all-out assault on MSPs\u00a0and MSP client systems, with ransomware halting businesses, harming reputations, and even resulting in some\u00a0high-value ransom payouts. In\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.cyberconservices.com\/wp-content\/uploads\/2019\/09\/scan-3963099__340.jpg?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":31367,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2019\/02\/28\/formjacking-is-the-new-favorite-hack-of-cyber-crooks\/","url_meta":{"origin":77302,"position":1},"title":"Formjacking Is the New Favorite Hack of Cyber Crooks","author":"Rick Backus","date":"February 28, 2019","format":false,"excerpt":"Every month, thousands of retail websites are targeted by cyber criminals, who insert a small piece of malicious code that allows them to snatch customers\u2019 credit card information. The hacking technique is called formjacking, and it\u2019s the virtual equivalent of putting a device on an ATM to skim debit card\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.cyberconservices.com\/wp-content\/uploads\/2019\/02\/application-3685436__340.jpg?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":77730,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2025\/03\/24\/cybersecurity-officials-warn-against-potential-ransomware-attacks-involving-email-vpns\/","url_meta":{"origin":77302,"position":2},"title":"Cybersecurity officials warn against potential\u00a0ransomware\u00a0attacks involving email, VPNs","author":"Rick Backus","date":"March 24, 2025","format":false,"excerpt":"A ransomware-as-a-service software called Medusa, which has launched ransomware attacks since 2021, has recently affected hundreds of people.","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2025\/03\/cyber-security-3194286_1280.jpg?fit=1200%2C720&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2025\/03\/cyber-security-3194286_1280.jpg?fit=1200%2C720&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2025\/03\/cyber-security-3194286_1280.jpg?fit=1200%2C720&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2025\/03\/cyber-security-3194286_1280.jpg?fit=1200%2C720&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2025\/03\/cyber-security-3194286_1280.jpg?fit=1200%2C720&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":43342,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2020\/09\/22\/ransomware-this-essential-step-could-help-you-make-it-through-an-attack\/","url_meta":{"origin":77302,"position":3},"title":"Ransomware: This essential step could help you make it through an attack","author":"Rick Backus","date":"September 22, 2020","format":false,"excerpt":"Plan for your organisation to become the victim of a ransomware or malware attack, even if you think it's extremely unlikely you'll be targeted because having an incident response plan will greatly reduce the impact if the worst happens. The advice is part of the National Cyber Security Centre's (NCSC)\u2026","rel":"","context":"In &quot;Ransomware&quot;","block_context":{"text":"Ransomware","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/ransomware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2016\/08\/13\/16\/49\/computer-1591018__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2016\/08\/13\/16\/49\/computer-1591018__340.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2016\/08\/13\/16\/49\/computer-1591018__340.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2016\/08\/13\/16\/49\/computer-1591018__340.jpg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":46052,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2021\/03\/25\/dearcry-ransomware-unleashed-in-microsoft-exchange-hack\/","url_meta":{"origin":77302,"position":4},"title":"DearCry Ransomware Unleashed In Microsoft Exchange Hack","author":"Rick Backus","date":"March 25, 2021","format":false,"excerpt":"Not that this real news to anyone paying attention to tech but it is not just about the hack. The real point here is there are far to many servers out there that cannot be patched because they are too old. Unfortunately many organizations look on IT infrastructure as a\u2026","rel":"","context":"In &quot;Exchange&quot;","block_context":{"text":"Exchange","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/exchange\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/06\/12\/19\/02\/artificial-intelligence-5291510__340.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/06\/12\/19\/02\/artificial-intelligence-5291510__340.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/06\/12\/19\/02\/artificial-intelligence-5291510__340.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/cdn.pixabay.com\/photo\/2020\/06\/12\/19\/02\/artificial-intelligence-5291510__340.jpg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":77378,"url":"https:\/\/blog.cyberconservices.com\/index.php\/2024\/04\/29\/hackers-are-carrying-out-ransomware-experiments-in-developing-countries\/","url_meta":{"origin":77302,"position":5},"title":"Hackers are carrying out ransomware experiments in developing countries","author":"Rick Backus","date":"April 29, 2024","format":false,"excerpt":"By ELLESHEVA KISSIN -\u00a0Cyber attackers are experimenting with their latest ransomware on businesses in Africa, Asia, and South America before targeting richer countries that have more sophisticated security methods. Hackers have adopted a \u201cstrategy\u201d of infiltrating systems in the developing world before moving to higher-value targets such as in North\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/blog.cyberconservices.com\/index.php\/category\/security\/cybersecurity\/"},"img":{"alt_text":"High resolution imAGE of hacker group picking an african country on A MAP with a dart.","src":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2024\/04\/High-resolution-imAGE-of-hacker-group-1.png?fit=1024%2C1024&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2024\/04\/High-resolution-imAGE-of-hacker-group-1.png?fit=1024%2C1024&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2024\/04\/High-resolution-imAGE-of-hacker-group-1.png?fit=1024%2C1024&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/blog.cyberconservices.com\/wp-content\/uploads\/2024\/04\/High-resolution-imAGE-of-hacker-group-1.png?fit=1024%2C1024&ssl=1&resize=700%2C400 2x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/77302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/comments?post=77302"}],"version-history":[{"count":1,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/77302\/revisions"}],"predecessor-version":[{"id":77307,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/posts\/77302\/revisions\/77307"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/media\/77306"}],"wp:attachment":[{"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/media?parent=77302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/categories?post=77302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cyberconservices.com\/index.php\/wp-json\/wp\/v2\/tags?post=77302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}