Kaseya disclosed a security incident in its on-premises VSA remote management platform after attackers exploited a zero-day vulnerability and pushed ransomware through managed service providers to downstream customers. The company ordered on-premises customers to immediately shut down VSA servers, precautionarily took its SaaS infrastructure offline, and said early impact appeared limited to fewer than 40 direct customers, while later estimates put the downstream toll at 800 to 1,500 businesses. Kaseya said SaaS customers were not found compromised, identified VSA as the only affected product, and worked with FireEye Mandiant, the FBI, CISA, and Emsisoft on containment, forensics, detection tools, hardening guidance, and patches before restoring services.
Researchers and media reports linked the campaign to the REvil ransomware gang, which used infrastructure associated with prior REvil operations and demanded $70 million in bitcoin for a universal decryptor. The attack caused international disruption, most visibly forcing Sweden’s Coop grocery chain to close about 800 stores after payment systems failed, while other Swedish organizations also reported outages. Kaseya later said fewer than 60 direct customers were affected and that it obtained a universal decryptor from a third party on July 21, distributing it with Emsisoft’s help; the company publicly stated it did not pay a ransom directly or indirectly to obtain the tool.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On 2021-08-04, Kaseya published an additional official notice related to the VSA incident, marking a further public update in its response after the July disclosures and decryptor announcements.
On 2021-07-26, Kaseya publicly stated that it did not pay a ransom, directly or indirectly, to obtain the universal decryptor. In the same update, it said fewer than 60 direct customers and fewer than 1,500 downstream businesses were impacted, and no SaaS customers were found compromised.
On 2021-07-21, Kaseya said it obtained a universal decryptor from a third party to help victims recover encrypted systems. The company worked with Emsisoft to validate and distribute the tool and later reported no issues with its use.
On 2021-07-08, KrebsOnSecurity reported that Kaseya had left its customer portal vulnerable to a flaw dating back to 2015 in software it developed. The report added new technical context about Kaseya's security posture during scrutiny following the VSA ransomware incident.
On 2021-07-07, Kaseya issued a startup readiness guide for on-premises VSA customers as part of preparations to safely restore affected servers. The guidance was part of the company's staged recovery process following patching and hardening work.
By 2021-07-06, Kaspersky had published technical details of the REvil attack chain affecting MSPs and downstream customers, describing a PowerShell-delivered dropper, Defender tampering, certutil decoding of agent.exe, and DLL side-loading of mpsvc.dll via MsMpEng.exe. The report also shared detection names, hashes, and telemetry showing more than 5,000 attack attempts across 22 countries.
On 2021-07-04, CISA and the FBI issued detailed guidance for MSPs and downstream customers affected by the Kaseya VSA supply-chain ransomware attack. The notice recommended use of the Kaseya VSA Detection Tool, MFA enforcement, restricted RMM administrative access, air-gapped backups, and temporary manual patch management aligned with vendor remediation guidance.
By 2021-07-03, the FBI and CISA were actively investigating the incident, and President Joe Biden directed U.S. intelligence agencies to determine responsibility. Authorities also issued reporting and defensive guidance for affected organizations.
By 2021-07-03, a ransom note tied to infrastructure previously used by REvil offered a universal decryptor in exchange for $70 million in bitcoin. The demand followed broader extortion of individual MSPs and customers affected by the campaign.
On 2021-07-03, the attack's downstream impact became visible internationally as affected MSP customers suffered outages. Sweden's Coop supermarket chain closed about 800 stores after cash registers stopped functioning, and other Swedish organizations also reported disruption.
By 2021-07-02, attackers had exploited a zero-day in Kaseya's on-premises VSA product to push ransomware through managed service providers to downstream organizations. Early reporting linked the campaign to REvil and indicated that administrative access to VSA was disabled as part of the attack chain.
On 2021-07-02, Kaseya disclosed a potential security incident affecting its VSA product and told all on-premises customers to immediately shut down their VSA servers. It said the issue appeared limited to a small number of on-premises customers, shut down SaaS servers as a precaution, and notified the FBI and CISA while engaging incident response experts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
26 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcehelpdesk.kaseya.com
Open sourcehelpdesk.kaseya.com
Open sourcehelpdesk.kaseya.com
Open sourcecommunity.sophos.com
Open sourceus-cert.cisa.gov
Open sourceweb.archive.org
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.