Kaseya Ransomware Attack Disrupts Over 1,000 Businesses Worldwide
A massive ransomware attack on software supplier Kaseya exploits managed service providers to indirectly compromise at least 1,000 downstream businesses. The breach, linked to the REvil group, forces major operations like Swedish supermarkets to close temporarily.
Software supplier Kaseya faces a sophisticated ransomware attack that potentially compromises thousands of downstream businesses. The breach targets Kaseya's VSA product and primarily impacts on-premises customers, though the company's CEO insists only a very small percentage of direct users experience issues.
The true scale of the attack remains unclear because compromised managed service providers (MSPs) pass the disruption down to their own clients. Cybersecurity researchers estimate that at least 1,000 small businesses and organizations suffer from this ripple effect, forcing major chains like Sweden's Coop to close 800 supermarket locations.
Experts link the attack to REvil, the Russian-speaking ransomware group responsible for previous high-profile breaches. Kaseya actively collaborates with the FBI, outside cybersecurity experts, and CISA to investigate the incident while urging all on-premises customers to keep their VSA servers offline until further notice.