What Happens When Your IT Provider's Own Tools Get Hacked

A vulnerability in a popular remote management tool let attackers push malware through the same system used to protect clients. Here's what to ask your IT provider about how they secure their own tools.

Your IT provider has a tool installed on every computer in your office. It’s how they push updates, run maintenance, troubleshoot issues, and monitor for problems. You’ve probably never thought about it. It runs in the background. It just works.

That tool is called an RMM (Remote Monitoring and Management) platform. It’s the backbone of how managed IT services operate. And in late June, attackers exploited a critical vulnerability in one of these platforms to push malware directly to the computers it was supposed to protect.

What happened

The platform was SimpleHelp, used by IT providers, helpdesks, and internal IT departments. The vulnerability (CVE-2026-48558) was an authentication bypass, meaning attackers could create their own admin sessions without needing a password. From there, they had the same access a legitimate technician would: connect to any managed machine and run commands.

Security firm Blackpoint documented an intrusion where attackers used this access to deploy a new malware strain called Djinn Stealer across managed endpoints. The malware harvested credentials, browser data, and configuration files from every machine it touched.

Roughly 1,000 SimpleHelp servers were exposed to the internet and vulnerable at the time of disclosure. Each one potentially managing dozens or hundreds of client machines.

Why this matters for your firm

Here’s the thing about managed IT: the tools designed to protect you are also the most powerful attack vectors if they’re compromised. Your IT provider’s RMM agent has administrative access to every workstation and server it manages. It can install software, run scripts, access files, and connect remotely. If an attacker gains control of it, they don’t need to phish your employees or guess passwords. They already have the keys.

This has happened before. Kaseya VSA was hit in 2021, affecting over 1,500 businesses through their IT providers. SolarWinds Orion was compromised in 2020, reaching 18,000 organizations. Attackers go after the management layer because one breach there cascades to every client underneath.

For a law firm or CPA firm, the stakes are higher than most. Your IT provider’s tools have access to client files, financial records, email, and privileged communications. A supply chain compromise doesn’t just affect your data. It exposes your clients’ data, which triggers notification obligations and potentially bar ethics issues.

Questions your IT provider should be able to answer

You don’t need to understand how RMM platforms work at a technical level. But you should be asking your provider some pointed questions about how they secure theirs.

How fast do you patch your own management tools? The SimpleHelp vulnerability had a patch available. Some providers applied it within hours. Others took days or longer. The difference matters when attackers are actively exploiting a flaw.

Do you monitor your own admin sessions? When someone logs into the management console, is that logged? Would you know if a rogue session appeared from an unexpected location? The attackers who exploited SimpleHelp created their own technician accounts. A provider with session monitoring catches that. One without doesn’t.

Who on your team can access our machines, and how is that controlled? Not every technician needs full admin access to every client at all times. Some providers use session approval workflows and time-limited access. Others give everyone the keys to everything. Ask which model yours uses, and whether you can see the access logs.

What’s your plan if your own platform is compromised? No vendor is immune. The question is whether your provider has a documented process for that scenario, or whether they’d be figuring it out on the fly while your systems are exposed.

If your primary tool goes down, can you still manage our environment? This one is less common, but worth asking. If the RMM platform itself is compromised and has to be shut down, does your provider have a backup access path, or are you both stuck?

If any of these questions get a defensive reaction or a vague answer, that tells you something.

Your IT provider’s infrastructure is part of your attack surface

Every managed IT provider uses remote management software. That’s how the service model works. The question is whether yours treats those tools as potential targets and secures them accordingly.

We wrote previously about what to look for when vetting an IT provider. This is a narrower version of that conversation, but it might be the more important one. The people who hacked SimpleHelp didn’t need to target your firm directly. They targeted your provider’s tools, and your firm came along for the ride.


Artech Solutions runs hardened management tools with session logging, least-privilege access, and patching timelines measured in hours. If you’re not sure how your current provider handles these questions, we can help you figure out what to ask.