MSP Executive Reveals How Community Support Saved Business From Kaseya Ransomware Attack
A managed service provider co-founder details the rapid 2021 Kaseya VSA ransomware attack and explains how vendor and peer support enabled a full recovery. The incident highlights the critical vulnerability of supply chain tools and the overwhelming demand such crises place on MSPs.
Progressive Computing co-founder Robert Cioffi shares a detailed account of the 2021 Kaseya VSA ransomware attack that disrupts his business and impacts 80 customers. REvil threat actors exploit a zero-day vulnerability in the remote monitoring and management tool to rapidly deploy ransomware to over 2,000 endpoints. Cioffi describes the incident as a classic "smash and grab" where attackers bypass security layers, create an admin account, and push malicious scripts without attempting targeted data exfiltration.
The attack triggers an immediate and overwhelming crisis as the MSP's phones ring off the hook with alerts from affected clients. Cioffi notes that MSPs operate by providing fractional services, but this event suddenly requires 100% support capacity for every single customer simultaneously. He admits that his organization simply does not have enough staff to handle such a massive, all-hands-on-deck situation by design.
Surviving the catastrophic outage relies heavily on external assistance from industry peers and technology vendors like Axcient and its X360Recover platform. Cioffi emphasizes that community support ultimately saves the 30-year-old MSP from ruin. He now urges other service providers to build strong relationships within the IT community before a disaster strikes.