Don’t do SECURITY. Do business SECURELY.

REvil ransomware spreads through Kaseya software to 1,500 businesses

REvil exploits Kaseya's VSA remote management software, hitting managed service providers and up to 1,500 downstream businesses.

The REvil ransomware group exploited a vulnerability in Kaseya VSA, remote management software used by managed service providers, to push ransomware to their customers. Kaseya said up to 1,500 downstream businesses were affected.

What happened

  • The attack began on 2 July 2021, ahead of the US Independence Day holiday weekend.
  • Around 60 Kaseya customers, mostly managed service providers, were directly compromised.
  • Swedish supermarket chain Coop closed hundreds of stores after its tills were disrupted.
  • REvil demanded $70 million for a universal decryptor; in November 2021 the US charged a Ukrainian national over the attack.

Why it mattered

The incident showed how attacking a single IT supplier could cascade to hundreds of businesses and intensified international action against ransomware groups. It also led to the arrest and extradition of a suspect, and REvil’s infrastructure went offline shortly after the attack.

Lessons for organisations

Assess the security of managed service providers and remote management tools, limit the access they have to your systems, and include supplier compromise in incident response plans. Make sure backups cannot be reached or deleted through the same remote management tools.

Source: The Record

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights