ThreatPaper
Unverified

The 3CX compromise put 600,000 businesses at risk

Assessment

The figure describes 3CX's installed base, not the population exposed by this incident. 3CX publishes "more than 600,000 customers and 12 million users" as its own marketing numbers, and that figure was carried into coverage of the compromise as though it measured the blast radius. Exposure was narrower by construction. The trojanised code shipped in specific builds — Windows Electron 18.12.407 and 18.12.416 in Update 7, and macOS Electron 18.11.1213, 18.12.402, 18.12.407 and 18.12.416 — so the exposed population is the subset of customers that installed one of those versions during the window they were available. That subset was never quantified publicly, by 3CX or by anyone else. The one hard number that exists points the other way. Kaspersky, which identified the second-stage Gopuram backdoor, observed it on fewer than ten machines, concentrated on cryptocurrency companies. Mass distribution appears to have functioned as a targeting funnel rather than as the objective. This claim is rated Unverified rather than False: no evidence establishes that 600,000 businesses were exposed, but neither has anyone published a figure that contradicts it. The problem is that an installed-base number was reused as an impact number without either being measured.

Where this claim appeared

CPO Magazine · 2023-03-30

https://www.cpomagazine.com/cyber-security/supply-chain-attack-on-voip-firm-3cx-puts-600000-businesses-at-risk-including-fortune-500-companies/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise

Think this assessment is wrong? Report an error.