- TeamViewer has been the primary medium for tech support scams that lock people out of their own PCs for years now. Despite a usage pattern that should be easy to detect, they've seemingly done nothing effective to curb this.
- TeamViewer is blaming insecure configuration, which is probably mostly true, but TeamViewer has refused to do much to encourage or ensure security practices are upheld. (Random six character passwords on by default?)
- TeamViewer has clearly failed to police large scale attempts to test credentials against their server, if they're using password dumps to find people using the same password elsewhere, as many people on Reddit confirmed was likely the case for them.
I strongly suspect the majority of free service TeamViewer usage is currently malicious. I know very few people who HAVEN'T been reached by a malicious party which uses TeamViewer as a communication medium.
I've personally called and asked TeamViewer to consider shuttering their free service to control malicious use. They could introduce an affordable personal use paid tier instead, which would make them a lot of money, and mitigate most abuse cases.