Citrix takes the safety and security of its customers very seriously, and is aware of the password attack on GoToMyPC. Once Citrix determined the nature of the attack, it took immediate action to protect customers. Citrix can confirm the recent incident was a password re-use attack, where attackers used usernames and passwords leaked from other websites to access the accounts of GoToMyPC users.
At this time, the response includes a mandatory password reset for all GoToMyPC users. Citrix encourages customers to visit the GoToMyPC status page to learn about enabling two-step verification, and to use strong passwords in order to keep accounts as safe as possible. Further, there is no indication of compromise to any other Citrix product line.
Frequently Asked Questions:
Q: What happened?
A: GoToMYPC (G2P) came under a password attack. Once we determined the nature of the attack, we took immediate action to protect our customers. Citrix can confirm the recent incident was a password re-use attack, where attackers used usernames and passwords leaked from other websites to access the accounts of GoToMyPC users.
Q: Was GoToMyPC the only product impacted by the attack?
A: Yes, GoToMyPC was the only product line effected. There is no indication any other product was impacted.
Q: What did Citrix do?
A: In order to protect our customers, we have set a mandatory password reset for all GoToMyPC users. We encourage our members to enable two-step verification, and to use strong passwords in order to keep their accounts as safe as possible.
Q: What should I do if I am a GoToMyPC customer?
A: To protect you, the GoToMYPC security team reset all customer passwords.
Next Steps: .
You will be required to reset your GoToMYPC password before you can login again.
To reset your password please use your regular GoToMYPC login link.
Recommendations for a strong password
• Don’t use a word from the dictionary
• Select strong passwords that can't easily be guessed with 8 or more characters
• Make it Complex – Randomly add capital letters, punctuation or symbols
• Substitute numbers for letters that look similar (for example, substitute “0” for “o” or “3” for “E”)
• Don't use the same password in more than one place
2-step Verification option
We recommend everyone use the 2-step Verification option for GoToMyPC accounts. http://support.citrixonline.com/en_US/gotomypc/help_files/GTC070021?title=2-Step+Verification
Q: Was any personal information compromised?
A: Our initial assessment indicates that no sensitive customer data (such as credit card information) was exposed. We are continuing an in-depth forensic investigation and will share the results of this investigation as soon as feasible.
Q: Where can we go find more information about the event?