I’d like to start with, we are big advocates for 3CX and it’s a very solid VoIP service. You can’t go wrong with over 500k customers and millions of users.
Remove any instances of devices with the 3CX desktop app acquired to the .msi installer. You may need to do more than that if your end users had admin privileges to their endpoints and/or you have a typical AD domain.
Switch to using the PWA (Progressive Web App) and/or standard desk phones. The PWA functions exactly the same without the compromise.
Continue watching network logs for the indicators of compromise.
Find a qualified service provider like RackSimply to help you mitigate this breach and provide you with an EDR or MDR solution to stay in front things like this.
Check your vendor contracts and ensure that service providers (SaaS, IaaS, NaaS, PaaS, etc) are stepping up to the plate to secure your data AND theirs. A breach will always come through the weakest link.
0