Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› AnyDesk Breach 2024: How a Production Compromise Forced…
Breach analysis Incident: 2 Feb 2024

AnyDesk Breach 2024: How a Production Compromise Forced a Code Signing Certificate Revocation and Portal Password Reset

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Category: NHI
Attack route: Not disclosed Identities: Signing key or certificate
On this page

On 2 February 2024, AnyDesk Software GmbH, the German maker of the widely used AnyDesk remote desktop tool, said attackers had compromised its production systems. The company said it had brought in CrowdStrike, revoked "all security-related certificates", would revoke the code signing certificate used for its software, and was revoking every password for its customer web portal, my.anydesk.com, as a precaution. BleepingComputer reported the same day that source code and private code signing keys had been stolen, which AnyDesk did not confirm. AnyDesk has not said how the attackers got in. Reports differ on when the intrusion began: Help Net Security says late December 2023, while The Hacker News cites AnyDesk as placing it in mid-January 2024. AnyDesk said it found no evidence that end-user devices were affected and, later, no evidence of malicious code distributed to customers. The incident matters because a code signing key is the identity a software vendor uses to vouch for its own programs.

Key takeaways

  • AnyDesk confirmed on 2 February 2024 that its production systems had been compromised, and said the incident was not ransomware. It did not disclose how the attackers got in.
  • The company revoked its security-related certificates and replaced its code signing certificate. BleepingComputer reported that private code signing keys and source code were stolen; AnyDesk did not confirm this.
  • AnyDesk reset all my.anydesk.com web portal passwords as a precaution. It said session authentication tokens could not be stolen and that it had no evidence of malicious code reaching customers.
  • Akamai advised that versions before 7.0.15 and 8.0.8 were signed with the revoked certificate and that the incident "should be treated as ongoing" because the attackers' intent was unknown.
  • The identity lesson: a code signing key is a machine identity trusted by millions of endpoints, so it must be held where a production intrusion cannot reach it, and replaced quickly when that fails.

At a glance

OrganisationAnyDesk Software GmbH (remote desktop software; more than 170,000 customers, according to the company)
WhenIntrusion began late December 2023 (Help Net Security) or mid-January 2024 (The Hacker News, citing AnyDesk); service outage from 29 January 2024; disclosed 2 February 2024
AttackerUnknown. AnyDesk has not attributed the attack and said it was not ransomware
Entry pointNot disclosed
Identities abusedAnyDesk's code signing certificate and private key (theft reported by BleepingComputer, not confirmed by AnyDesk); other security-related certificates; customer web portal passwords reset as a precaution
ImpactProduction systems compromised; code signing certificate revoked and replaced; all portal passwords reset; no evidence of affected end-user devices or malicious code distributed, according to AnyDesk
CategoryNHI. Incident class: confirmed NHI breach (production compromise that forced revocation of the vendor's code signing identity)

What happened

AnyDesk is remote access software used by IT support teams and managed service providers to connect to computers they look after. In late January 2024 users noticed problems. On 24 January AnyDesk warned of intermittent timeouts on its customer portal, and from 29 January, according to Günter Born as reported by BleepingComputer, it suffered a four-day outage during which client logins were disabled. Its status page called it maintenance. On 29 January it also released version 8.0.8, signed with a new certificate. On 2 February security researcher Kevin Beaumont flagged a possible hack, writing: "They just had a several day authentication outage they describe as 'planned maintenance' (it wasn't planned)".

AnyDesk published its statement that evening. It said it had found indications of an incident on its production servers, confirmed a compromise in a security audit and activated a response plan with CrowdStrike. "We have revoked all security-related certificates and systems have been remediated or replaced where necessary," the company said. "We will be revoking the previous code signing certificate for our binaries shortly." It added: "As a precaution, we are revoking all passwords to our web portal, my.anydesk.com," and "To date, we have no evidence that any end-user devices have been affected." AnyDesk said its systems were designed not to store private keys, security tokens or passwords that could be used to connect to end-user devices.

BleepingComputer went further: "BleepingComputer has learned that source code and private code signing keys were stolen during the attack." It did not name its source, and AnyDesk did not say whether any data was stolen. BleepingComputer noted that older executables were signed as "philandro Software GmbH" and new ones as "AnyDesk Software GmbH". AnyDesk told it: "AnyDesk is designed in a way which session authentication tokens cannot be stolen."

The following day Resecurity reported that a seller was offering 18,317 AnyDesk customer accounts for $15,000 on the Exploit.in forum, The Hacker News reported. AnyDesk said "they appear to be old information obtained from end-user devices infected with malware", and Help Net Security described them as apparently unrelated to the breach. In an update on 8 February, AnyDesk said it had found no malicious changes to its source code and said: "We also have no evidence of malicious code being distributed to customers through any AnyDesk systems."

Timeline

DateEvent
December 2023The intrusion begins in late December, according to Help Net Security's 8 February update; The Hacker News cites AnyDesk as placing it in mid-January 2024.
24 January 2024AnyDesk warns of intermittent timeouts and degraded service on its customer portal.
29 January 2024A multi-day outage begins with client logins disabled; version 8.0.8 is released with a new code signing certificate.
2 February 2024Kevin Beaumont flags a possible hack; AnyDesk confirms the production compromise, revokes certificates and resets portal passwords.
3 February 2024Resecurity reports 18,317 AnyDesk customer credentials offered for sale; AnyDesk says they appear to come from infostealer infections.
7 February 2024Akamai publishes hunting guidance for executables signed with the revoked certificate.
8 February 2024AnyDesk says it found no malicious code changes and no evidence of malicious code distributed to customers.

How it happened: the identity attack path

  1. Unknown initial access. Attackers reached AnyDesk's production environment by a route the company has not disclosed.
  2. Presence in production. The compromise was serious enough that AnyDesk revoked all security-related certificates and remediated or replaced systems, with CrowdStrike assisting.
  3. Signing identity exposed. AnyDesk treated its code signing certificate as no longer trustworthy and replaced it. BleepingComputer reported that the private code signing keys were stolen.
  4. Customer credentials reset. AnyDesk revoked all web portal passwords as a precaution, while saying its systems do not hold credentials that connect to end-user devices.
  5. Trust rebuilt on a new key. Customers were told to install releases signed with the new certificate, and defenders were given the old certificate's serial number to hunt for anything else signed with it.

Impact

  • Confirmed: AnyDesk's production systems were compromised; all security-related certificates were revoked; the code signing certificate was replaced; every my.anydesk.com password was reset.
  • Reported, not confirmed by AnyDesk: theft of source code and private code signing keys, according to BleepingComputer.
  • Potential: with a stolen signing key, attackers could sign malware as AnyDesk and evade security tools, Akamai warned. Akamai said it saw AnyDesk in about 25% of the networks it monitors.
  • Not found: AnyDesk reported no evidence of affected end-user devices, session hijacking or malicious code distributed to customers. The credentials offered for sale were attributed to infostealer malware, not the breach.

What this means for NHI governance

A code signing certificate and its private key form one of the most powerful machine identities a software company owns. Every computer that runs AnyDesk trusts code because it carries that signature. If the key leaves the company, anyone holding it can make malware look like a genuine AnyDesk release. That is why the response centred on revoking and replacing the certificate, and why customers and security teams then had to hunt for binaries signed with the old one.

The incident also shows what revocation costs when a signing identity has been used for years. Every legitimate older release becomes suspect, and customers must upgrade. Keeping signing keys in hardware security modules or managed signing services, separating them from the production systems that attackers are most likely to reach, and having a tested plan to rotate them limits that damage. Our Machine Identity, PKI and Certificate Lifecycle Guide and Cryptographic Key Management Guide cover these controls.

Recommendations

  • Keep code signing keys in hardware or a managed signing service. The private key should never be exportable to build or production servers. See our Cryptographic Key Management Guide.
  • Prepare a signing key revocation plan before you need it. Know how you will issue a new certificate, re-sign current releases and tell customers which versions to trust. See our Machine Identity, PKI and Certificate Lifecycle Guide.
  • Hunt for binaries signed with a revoked certificate. As Akamai advised, search endpoints for executables carrying the old certificate's serial number and check remote access tools for unexpected behaviour.
  • Inventory and govern remote access tools. Find every AnyDesk installation, including unsanctioned ones, and restrict remote access software to approved, current versions. See our Remote Access Identity Guide.
  • Reset vendor portal credentials and stop reuse. Change passwords for vendor portals after a supplier breach, enable MFA and check whether the same passwords were used elsewhere. See our Password Security Guide.
  • Treat suppliers' signing identities as third-party risk. Ask critical software vendors how they protect and rotate their signing keys. See our Third-Party Access Guide.

Frequently asked questions

What happened in the AnyDesk breach?

On 2 February 2024 AnyDesk said attackers had compromised its production systems. It revoked its security certificates and code signing certificate, reset all web portal passwords and worked with CrowdStrike to remediate. It has not said how the attackers got in.

Was the AnyDesk code signing certificate stolen?

BleepingComputer reported that private code signing keys and source code were stolen. AnyDesk did not confirm this but revoked the certificate and released new versions signed with a replacement. Akamai said versions before 7.0.15 and 8.0.8 were signed with the revoked certificate.

Is AnyDesk safe to use after the breach?

AnyDesk said it had no evidence that end-user devices were affected or that malicious code was distributed through its systems, and advised users to install the latest version signed with the new certificate and change any reused passwords.

GitHub Code Signing Certificate Theft 2022 · MSI Signing Keys Leak 2023 · Storm-0501 Hybrid Cloud Attack 2024 · Machine Identity, PKI and Certificate Lifecycle Guide · Cryptographic Key Management Guide

How NHI Mgmt Group can help

Signing keys and certificates are machine identities that few organisations inventory or rehearse replacing. We help teams find them, protect them and plan their rotation. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org