// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / ConnectWise
Breach Record

ConnectWise

DISCLOSED 2024-03-01 · RANSOMWARE · RANSOMWARE

Attackers exploited a critical authentication bypass vulnerability (CVE-2024-1709) in ConnectWise ScreenConnect to deploy Play ransomware and attempt a LockBit supply chain attack via an MSP. The vulnerability allows unauthenticated creation of administrative users, granting full system control. Multiple ransomware strains were observed in the wild within days of disclosure.

The record

What we know

Disclosed
2024-03-01
Attack vector
Ransomware
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other ransomware breaches on file

This page is the permanent ColdRecon entry for the ConnectWise disclosure. It updates if new public reporting emerges. All tracked breaches →

ConnectWise just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →