We regret to inform you that our company has become victim to an attack on our product and the larger supply chain. Our highest priority is to be transparent in sharing details on what actions we are taking in response to this incident and what we know to date. Information is rapidly unfolding in this ongoing investigation. We want to ensure we only share validated information with actionable steps for you to take. We’ll continue working closely with our Mandiant advisers to investigate how this incident occurred and put in place measures to prevent any recurrence.

What Happened?

On March 29th, 3CX received reports from a third party of a malicious actor exploiting a vulnerability in our product. We took immediate steps to investigate the incident, retaining Mandiant, leading global cybersecurity experts. Initial investigation suggested the incident was carried out by a highly experienced and knowledgeable hacker. We’re working closely with law enforcement and other authorities.

What 3CX is Doing?

  • With Mandiant by our side, we’re conducting a full investigation. This includes a thorough security review of our Web Client and PWA App where Mandiant engineers are validating the entire source code of our web app and Electron App for any vulnerabilities.
  • In addition, we’ve received an outpouring of support from the security industry and research community to share insights and data related to our investigation.

What We Recommend You Do Now

  1. Uninstall the 3CX Electron Desktop Application from all Windows or Mac OS computers. See more information here.
  2. Continue AV scans and EDR solutioning in your organization's networks for any potential malware with the latest signatures.
  3. Switch to using the PWA Web Client App rather than Desktop App. Read more about this here and how to switch to PWA.
    1. For installation, go to the 3CX Web Client
    2. Click “Install 3CX” on top of your address bar. It doesn’t require installing any binary and runs within your browser sandbox.

How Do I Get the Latest Developments?

3CX is taking this opportunity to continue to strengthen our policies, practices, and technology to further protect against future attacks. For the latest developments:

  1. Subscribe to 3CX’s RSS feed. This blog is where we will provide all our updates on this ongoing investigation.
  2. Dedicated Support Forum & 3 Free Support Tickets - To answer as many questions as possible we’ve set up a dedicated help forum including 3 support tickets for all users.
    1. Log into your 3CX portal account.
    2. Click "More" menu top right.
    3. Select "Support".
    4. Click "Create ticket".
    5. Select the instance you want to ask a question about.
    6. Enter support question - auto reply receipt confirmation followed later by response
  3. Follow us on Social Media - For the latest updates please follow us on our social media channels. Alerts will be posted on Twitter and LinkedIn alerting to blog updates .

In Appreciation of Our Customers & Partners for Your Patience and Support

We value our customers and partners and want to continue providing an exceptional product to all we serve. As a token of gratitude for your patience and support, we are extending customers’ subscriptions by 3 months free of charge. Partners have received an email with details on this too. This extension will be applied automatically in the coming weeks. Updates to follow.

And Last But Not Least Thank You

We’ve been overwhelmed by the swell of support from our partners and customers who have actively supported us on the forums with practical advice and moral support. Thank you! To the countless security researchers and experts that have published information about the attack and have helped us and our customers navigate the attack, we are also truly thankful. We will continue to provide additional information as we have more to share.