Hackers are targeting VPNs to gain access to enterprise systems

A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light
(Image credit: Getty Images)

Software company Check Point has warned that hackers are targeting its Remote Access VPN devices in order to gain access to enterprise networks.

This discovery comes shortly after cyber insurance company At-Bay published research that remote access tools were the intrusion point for 58% of ransomware attacks in 2023.

In an advisory published on May 27, the software company explained that the cyber attacks were discovered after a "small number" of login attempts were flagged. These login attempts targeted old local VPN accounts that used insecure password-only authentication. 

In order to improve their security, Check Point has recommended that its customers check their local accounts to see both if they have them, and to see if they have been used and who has used them. If users have local accounts they're not using, Check Point says it's best to just disable them. 

Olivia Powell
Tech Software Commissioning Editor

Olivia joined Tom's Guide in October 2023 as part of the core Tech Software team, and is currently VPN Commissioning Editor. She regularly uses VPNs to make sure they deliver what they promise, and specializes in testing VPNs with streaming sites.