In brief: In 2023, 3CX experienced a significant supply chain attack where a compromised version of its desktop app was distributed to customers. The incident is a case study in supply chain security risks — and the lessons apply to all software your clients run, not just 3CX.
The 3CX Supply Chain Attack: What Happened
In late March 2023, security researchers at CrowdStrike and Sophos identified a trojanised version of the 3CX desktop application being distributed from 3CX’s own update infrastructure. The attack — attributed by multiple security researchers to Lazarus Group, a North Korea-affiliated threat actor — had compromised the build pipeline used to create 3CX’s Windows desktop app, injecting malicious code before the software was signed and distributed.
The attack affected users who had auto-updates enabled and downloaded 3CX desktop app versions 18.12.407 and 18.12.416. The malicious code was designed to beacon to attacker-controlled infrastructure and could be used to deliver additional malware payloads to affected systems.
3CX responded swiftly: suspending the compromised app, releasing a clean version (V18 U7a) with enhanced security measures, and initiating a comprehensive security review. The company engaged CrowdStrike and other security firms to assist with the investigation and remediation.
V18 U7a: The Security Response
3CX’s V18 Update 7a was the immediate security response release. Key changes in U7a included:
- Removal of the compromised code and distribution of a clean app build
- Enhanced build pipeline security controls to prevent future code injection attacks
- Improved binary signing and verification procedures
- Recommendations for customers to uninstall affected versions and reinstall from clean sources
- Guidance for security teams on indicators of compromise (IOCs) for affected systems
SA resellers managing 3CX deployments at the time of the attack needed to take immediate action: notify clients, remove affected app versions, deploy U7a, and in some cases escalate to the client’s security team for a threat assessment.
Supply Chain Attacks: The Broader Context
The 3CX incident is one of several high-profile supply chain attacks in recent years. SolarWinds (2020) and Kaseya (2021) demonstrated that attacking the software supply chain — compromising a trusted vendor’s update infrastructure — can give attackers access to thousands of end-user environments simultaneously. This attack vector is particularly insidious because users trust software from vendors they’ve verified and paid for.
For telecoms resellers, the 3CX attack highlights a risk category that most clients don’t think about: the software they install from trusted vendors could itself be compromised at the source. This isn’t an argument against using 3CX (which responded professionally and quickly) but rather an argument for understanding that no software is immune to supply chain risk.
What the Incident Revealed About 3CX’s Maturity
3CX’s response to the 2023 attack actually demonstrated significant organisational maturity. The company communicated rapidly and transparently, engaged credible external security partners, implemented technical fixes quickly, and published comprehensive guidance for affected customers. This crisis response stands in contrast to vendors who try to minimise or conceal security incidents.
Post-incident, 3CX implemented ongoing security improvements including:
- Two-factor code signing for all builds
- Enhanced monitoring of build pipeline integrity
- More rigorous third-party dependency auditing
- Faster communication protocols for security incidents
The version released after the incident (V18 U7a and subsequent releases) was more secure than what preceded it. Resellers who maintained client trust through the incident by communicating proactively came out stronger.
Lessons for SA Telecoms Resellers
Have a software incident response plan: When a vendor publishes a critical security update or incident disclosure, you need to be able to notify affected clients and apply fixes quickly. This requires knowing which clients are running which software versions — a managed service inventory that many resellers don’t maintain rigorously.
Monitor vendor security communications: Subscribe to security alerts from all your key vendors (3CX, Yeastar, Sangoma, etc.). 3CX maintains a security disclosure process and will publish advisories for significant vulnerabilities. Following these promptly is a professional obligation.
Educate clients on software update hygiene: Auto-updates are convenient but can be a vector for supply chain attacks. For business-critical systems, consider a staged update policy: apply updates to a test environment first, then roll out to production after 24–48 hours if no issues are reported by the community. This doesn’t apply to emergency security patches, which should be applied immediately.
Understand your incident communication obligations: If a vendor discloses a security incident affecting software you’ve deployed for clients, you have an obligation to notify those clients and guide them through remediation. POPIA’s information regulator expects reasonable security measures; deploying unpatched compromised software is not reasonable.
Use endpoint security on systems running 3CX clients: Business-grade endpoint detection and response (EDR) on systems running VoIP desktop clients provides an additional layer of detection if a supply chain attack delivers malware. This is particularly relevant for businesses that have sensitive data on the same endpoints running 3CX.
Current 3CX Security Posture
As of 2025, 3CX has completed a comprehensive security overhaul and has been independently audited by leading security firms. The platform is considered secure for business deployment. Resellers should ensure all client deployments are running current versions (V20 U2 or later) and that the legacy V18 client application has been removed from all endpoints.
What This Means for SA Telecoms Resellers
The 3CX supply chain attack was a significant industry event, but 3CX’s professional response and subsequent security improvements have strengthened rather than weakened the platform’s credibility in the long term. SA resellers who want to address the incident proactively in client conversations: be factual, acknowledge the seriousness, explain the response, and point to 3CX’s current security posture as evidence of appropriate vendor behaviour.
Use the incident as a prompt to audit your own client portfolio for version currency, ensure your managed service offering includes security update notifications, and review your incident response procedures so you’re prepared for the next security event — from any vendor.