Ransomware Breach at Florida IT Firm Kaseya Hits 200 Businesses

The attackers changed a Kaseya tool called VSA, used by companies that manage technology at smaller businesses.

Advertisement
By Reuters | Updated: 3 July 2021 10:21 IST
Highlights
  • Technology management software Kaseya was targeted by a ransomware attack
  • Kaseya said it's investigating a "potential attack"
  • Russia-linked REvil ransomware gang could be behind the attack

The ransomware attack impacted hundreds of American businesses on Friday

Photo Credit: Pexels/ Sora Shimazaki

Hundreds of American businesses were hit Friday by an unusually sophisticated ransomware attack that hijacked widely used technology management software from a Miami-based supplier called Kaseya. The attackers changed a Kaseya tool called VSA, used by companies that manage technology at smaller businesses. They then encrypted the files of those providers' customers simultaneously.

Security firm Huntress said it was tracking eight managed service providers that had been used to infect some 200 clients.

Kaseya said on its own website that it was investigating a "potential attack" on VSA, which is used by IT professionals to manage servers, desktops, network devices, and printers.

Advertisement

It said it shut down some of its infrastructure in response and that it was urging customers that used VSA on their premises to immediately turn off their servers.

Advertisement

"This is a colossal and devastating supply chain attack," Huntress senior security researcher John Hammond said in an email, referring to an increasingly high profile hacker technique of hijacking one piece of software to compromise hundreds or thousands of users at a time.

Hammond added that because Kaseya is plugged in to everything from large enterprises to small companies "it has the potential to spread to any size or scale business." Many managed service providers use VSA, although their customers may not realise it, experts said.

Advertisement

Some employees at service providers said on discussion boards that their clients had been hit before they could get a warning to them.

Reuters was not able to reach a Kaseya representative for further comment. Huntress said it believed the Russia-linked REvil ransomware gang - the same group of actors blamed by the FBI for paralysing meat packer JBS last month - was to blame for the latest ransomware outbreak.

Advertisement

Demands for ransom
A private security executive working on the response effort said that ransom demands accompanying the encryption ranged from a few thousand dollars to $5 million (roughly Rs. 37.38 crores) or more.

The corruption of an update process shows a marked escalation in sophistication from most ransomware attacks, which take advantage of security loopholes such as common passwords without two-factor authentication.

An email sent to the hackers seeking comment was not immediately returned. In a statement, the US Cybersecurity and Infrastructure Security Agency said it was "taking action to understand and address the recent supply-chain ransomware attack" against Kaseya's VSA product.

Supply chain attacks have crept to the top of the cybersecurity agenda after the United States accused hackers of operating at the Russian government's direction and tampering with a network monitoring tool built by Texas software firm SolarWinds.

Kaseya has 40,000 customers for its products, though not all use the affected tool.

© Thomson Reuters 2021


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G67 Power 5G Specifications Revealed: See Storage Variants, Features
  2. OnePlus Ace 6 Pro Max Retail Box Leak Hints at Imminent Launch, Key Features
  3. This Is How You Can Get ChatGPT Go Subscription for Free
  4. Vivo X300 Ultra Features Leaked; May Arrive With This Snapdragon Chip
  5. Lava Agni 4 Confirmed to Feature Aluminium Frame, New Dedicated Button
  6. Episodic Superhero Game Dispatch Sells 1 Million Copies in 10 Days
  7. OpenAI Turns to Amazon in $38 Billion Cloud Services Deal After Restructuring
  8. Samsung Galaxy S26 Ultra Said to Get a Major Design Upgrade
  1. Dispatch, Episodic Superhero Game Starring Breaking Bad's Aaron Paul, Sells 1 Million Copies in 10 Days
  2. Nothing Phone 3a Lite Owners Can Uninstall Meta Services After Company Faces Backlash Over Preloaded Apps
  3. Lovable Partners With Guardio to Detect and Block Malicious Websites Created via Vibe Coding
  4. Stream Finance Discloses $93 Million Loss After Probe, Halts Operations
  5. Samsung Galaxy S26 Series Price Hike Likely Due to Rising Price of Key Components: Report
  6. Hong Kong Unveils Fintech 2030 Strategy to Accelerate AI, RWA Tokenisation
  7. Raat Akeli Hai: The Bansal Murders to Release on OTT Soon: Everything You Need to Know
  8. OpenAI Faces Backlash from Studio Ghibli, Bandai Namco Over AI-Generated Anime Videos
  9. OnePlus Ace 6 Pro Max Retail Box Leak Hints at Imminent Launch, Snapdragon 8 Gen 5 SoC
  10. Nintendo Switch 2 Crosses 10 Million Units Sold, Nintendo Hikes Full-Year Sales Forecast
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.