Production systems compromised — certificate and portal credentials rotated
In early 2024, AnyDesk confirmed that attackers had compromised some of its production systems. The remediation it disclosed shows what was at stake: the company revoked and replaced its code-signing certificate, and reset every password for the my.anydesk.com customer portal as a precaution. AnyDesk reported finding no evidence that end-user devices were affected.
The takeaway is not that AnyDesk responded badly — it disclosed the incident and rotated what needed rotating. The takeaway is that a remote desktop vendor’s central infrastructure sits inside your threat model whether you think about it or not. If the vendor holds certificates and credentials that matter to your machines, a breach of the vendor is, transitively, a problem for you.