Massive Supply Chain Ransomware Attack Exploits Kaseya VSA Software
The REvil ransomware group exploits a vulnerability in Kaseya's VSA software to compromise over 1,000 businesses through a supply chain attack. Kaseya later obtains a universal decryptor tool to help victims restore their encrypted data without paying the demanded $70 million ransom.
The REvil ransomware group launches a massive supply chain attack on July 2, 2021, by exploiting unpatched vulnerabilities in Kaseya VSA software. This remote management tool serves as a gateway for the hackers to compromise approximately 60 managed service providers and ultimately disrupt over 1,000 downstream businesses. The attackers demand a staggering 70 million USD in Bitcoin to unlock the encrypted systems.
Security researchers actually discover multiple zero-day vulnerabilities in the Kaseya VSA platform months earlier in April 2021 and report them to the company. However, Kaseya fails to patch all of the identified flaws before REvil weaponizes an authentication bypass bug to push malicious payloads to managed systems. In response to the breach, Kaseya immediately takes its cloud servers offline and issues urgent security advisories to all of its customers.
The widespread incident causes major operational downtime for affected organizations, including notable companies like the Swedish supermarket chain Coop. Fortunately, Kaseya announces on July 23 that a trusted third party provides a universal decryptor tool, allowing victims to recover their data without paying the ransom. Authorities later identify and sentence suspects involved in the devastating cyberattack.