Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

New Major Ransomware Attack Strikes IT Solutions Provider, Kaseya

New-Major-Ransomware-Attack-Strikes-IT-Solutions-Provider

Quick answer: On July 2, 2021, the REvil ransomware group exploited a zero-day in Kaseya VSA, a remote monitoring tool used by managed service providers (MSPs), compromising roughly 60 MSPs and up to 1,500 downstream businesses in one of the largest software supply chain ransomware attacks on record. MSPs should audit RMM exposure, enforce least-privilege access, and monitor code-signing certificates to prevent repeats.

Key Takeaways

  • On July 2, 2021, the REvil (Sodinokibi) ransomware-as-a-service (RaaS) group exploited an authentication bypass zero-day in Kaseya VSA, a remote monitoring and management (RMM) tool.
  • Roughly 60 managed service providers (MSPs) were directly compromised, and estimates put downstream businesses affected at 800 to 1,500, including Coop Sweden’s approximately 800 grocery stores.
  • REvil demanded a $70 million ransom on July 5, 2021. Kaseya shipped a patch on July 11, 2021, and did not pay the ransom.
  • A universal decryptor reached Kaseya through an unnamed third party by July 22 to 23, 2021.
  • Law enforcement disrupted REvil across late 2021 and early 2022, including an arrest in Poland in October 2021 and Russia’s FSB detaining 14 alleged members in January 2022.
  • The lasting lesson is that RMM platforms and code-signing trust chains are high-value, single points of failure for supply chain attacks, and that lesson is still directly relevant in 2026.

Published: July 2021. Updated: August 2026. Reviewed by Encryption Consulting’s security team.

Update Log

This post originally ran on July 9, 2021, days after the attack, as real-time news coverage. As of August 2026, it has been rewritten as a retrospective case study. The word “new” has been removed from the title and body because the Kaseya VSA attack is now a five-year-old, well-documented historical incident, not breaking news, and describing it as new would mislead readers. This update corrects that framing, verifies every fact and date against primary and reputable secondary sources, adds a full timeline, impact assessment, remediation checklist, decision table, limitations section, and FAQ, and refreshes the schema markup and internal links.

What Happened in the Kaseya VSA Attack?

On July 2, 2021, the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, an on-premises and cloud remote monitoring and management (RMM) tool that MSPs use to administer their customers’ networks and endpoints. A supply chain attack is one where an attacker compromises a trusted vendor or tool in order to reach that vendor’s downstream customers, rather than attacking each victim directly. By compromising a single RMM platform, REvil reached hundreds of MSPs and, through them, potentially thousands of small and mid-size businesses in a single operation.

The vulnerabilities behind the attack were not unknown to Kaseya. Dutch Institute for Vulnerability Disclosure (DIVD) researcher Wietse Boonstra had identified several zero-day flaws in VSA, including an authentication bypass now tracked as CVE-2021-30116, and reported them to Kaseya starting April 6, 2021. Kaseya was working through a coordinated disclosure and patch process with DIVD when REvil exploited the flaws before the fix shipped.

Primary-Source Timeline

  • April 6 to 6+, 2021: DIVD researcher Wietse Boonstra reports multiple VSA zero-day vulnerabilities to Kaseya; Kaseya and DIVD begin coordinated remediation.
  • July 2, 2021 (Friday, US holiday weekend): Kaseya’s incident response team detects the attack and tells on-premises VSA customers to shut down their servers immediately; Kaseya proactively takes its SaaS servers and data centers offline.
  • July 3, 2021: Kaseya publicly confirms it was targeted in a coordinated attack.
  • July 5, 2021: REvil publishes a $70 million ransom demand in Bitcoin for a universal decryptor covering all victims.
  • July 11 to 12, 2021: Kaseya releases the on-premises VSA patch and restores SaaS infrastructure.
  • July 13, 2021: REvil’s public infrastructure and leak sites go dark.
  • July 22 to 23, 2021: Kaseya announces it obtained a universal decryptor from an unnamed trusted third party and confirms it did not pay REvil’s ransom.
  • October 8, 2021: Ukrainian national Yaroslav Vasinskyi, charged in connection with the attack, is arrested in Poland.
  • November 8, 2021: The US Department of Justice unseals indictments against Vasinskyi and Russian national Yevgeniy Polyanin, and the US announces it seized over $6 million in ransomware proceeds.
  • January 14, 2022: Russia’s Federal Security Service (FSB), acting on a US request, raids REvil-linked addresses and detains 14 alleged members.
  • March 3, 2022: Vasinskyi is extradited to the United States.
  • May 1, 2024: Vasinskyi is sentenced to 13 years and 7 months in connection with over 2,500 ransomware attacks, including Kaseya.

What Technologies Were Affected?

The attack targeted Kaseya VSA directly, then propagated through the trust relationship between VSA and every downstream environment it managed. Kaseya VSA is remote monitoring and management (RMM) software: a category of tool that gives an MSP centralized, privileged access to patch, monitor, and administer many customer networks from one console. REvil abused an authentication bypass in the VSA web interface to reach the server without valid credentials, then used SQL injection to run code on it. The malicious payload was pushed out through VSA’s own automatic update mechanism disguised as a routine “Kaseya VSA Agent Hotfix,” so every MSP and endpoint trusting that update channel received the ransomware automatically. Attackers also used a fraudulently obtained code-signing certificate to make the payload appear legitimately signed, which is why certificate and code-signing hygiene sits at the center of the defensive lessons below.

What Was the Impact of the Kaseya Attack?

Roughly 60 MSPs were directly compromised, and public estimates of downstream businesses affected range from about 800 to 1,500, with some analyses citing figures as high as 2,000 organizations once indirect effects are included. The most visible consumer-facing impact was in Sweden, where Coop, a supermarket chain served indirectly through the Kaseya-managed IT provider Visma, had to close roughly 800 stores for nearly a week while it rebuilt point-of-sale systems rather than pay a ransom. REvil’s $70 million demand was one of the largest ransom demands publicly disclosed at the time. Kaseya has stated it did not pay any ransom to REvil.

How Was the Attack Detected and Contained?

Kaseya’s incident response team identified the intrusion on July 2, 2021, and moved within hours to instruct every on-premises VSA customer to shut their servers down immediately, before most victims had any visible symptoms. Kaseya simultaneously pulled its own SaaS servers and data centers offline as a precaution, even though those environments were not confirmed compromised, to prevent the same update channel from being used against SaaS customers. Kaseya then worked with outside incident response firms, the FBI, and CISA (the US Cybersecurity and Infrastructure Security Agency) while building and testing the eventual patch, rather than rushing a fix that might reopen the same hole.

Kaseya Attack Remediation Checklist: How MSPs Can Prevent a Repeat

The direct answer: no single control would have stopped the Kaseya attack, but the following steps close the specific gaps it exploited, and they apply to any MSP or enterprise running centralized remote-access or automatic-update tooling today.

  1. Inventory every RMM, remote-access, and automatic-update tool as a crown-jewel asset, with an owner and a patch SLA tied to vendor advisories.
  2. Enforce multi-factor authentication and least-privilege administrative access on every RMM console, and disable direct internet exposure of on-premises management interfaces where possible.
  3. Segment the network path between an MSP’s management plane and each customer environment so one compromised tenant cannot reach every other tenant.
  4. Monitor and inventory code-signing certificates and keys, and treat an unexpected or newly issued signing certificate as a possible indicator of compromise, not routine activity.
  5. Verify software updates out of band before they execute broadly, using application allow-listing or staged rollout rather than trusting a single automatic push to every endpoint at once.
  6. Maintain offline or immutable backups and test restoration regularly, since Coop Sweden’s fastest path back to operation was a clean rebuild, not decryption.
  7. Build a supply chain-specific incident response and customer-notification plan before an incident, covering how an MSP communicates a compromise to every downstream customer within hours, not days.

Lessons for 2026: Why the Kaseya Attack Still Matters

Five years on, the Kaseya attack still matters because the underlying conditions have not gone away. Ransomware-as-a-service continues to lower the skill barrier for launching large-scale attacks, and software supply chain attacks remain one of the fastest-growing categories of intrusion, a trend our team has tracked in State of Software Supply Chain Attacks and Top 10 Supply Chain Attacks that Shook the World. RMM tools, CI/CD pipelines, and code-signing infrastructure are still attractive to attackers precisely because compromising one of them buys access to many organizations at once, and the shift toward AI-assisted tooling and agent-to-agent automation only expands that attack surface. Organizations planning for post-quantum cryptography migration should also treat this as a preview of crypto-agility under pressure: the faster an organization can rotate keys, revoke a compromised certificate, and verify what is actually signed and trusted in its environment, the faster it recovers from an incident like this one.

Attack Stage, What Happened, and the Defensive Control That Would Have Helped

Attack StageWhat HappenedDefensive Control That Would Have Helped
Initial accessREvil exploited an authentication bypass zero-day (CVE-2021-30116) in Kaseya VSA’s web interface.Faster patch SLA on vendor-reported vulnerabilities and network segmentation limiting internet exposure of RMM consoles.
Code executionAttackers used SQL injection to run commands on the compromised VSA server.Web application firewalling and input validation on management interfaces.
Trust exploitationThe payload used a fraudulently obtained code-signing certificate to appear legitimately signed.Certificate lifecycle management and continuous monitoring for unauthorized or anomalous certificate issuance.
PropagationA malicious “hotfix” was pushed automatically through VSA’s own update channel to MSPs and their customers.Out-of-band update verification and staged or allow-listed software rollout.
ImpactFiles were encrypted across an estimated 800 to 1,500 downstream businesses; REvil demanded $70 million.Offline, immutable backups with regularly tested restoration.
RecoveryKaseya shipped a patch on July 11, 2021, and obtained a universal decryptor by July 22 to 23, 2021.A pre-built incident response and downstream customer-notification runbook.

Limitations

Exact figures for this attack still vary by source. Kaseya’s own early statements referenced a “small number” of on-premises customers, while independent researchers and later reporting put the number of directly compromised MSPs at roughly 60 and downstream businesses anywhere from 800 to 1,500 or higher, because many affected companies never publicly disclosed impact. Some details, including the precise mechanism by which the universal decryptor reached Kaseya and the extent of the FBI’s advance knowledge, were reported by outlets such as the Washington Post but were never fully confirmed by an official government statement. Legal outcomes for individuals connected to the attack have also continued to evolve well past the original 2021 news cycle, so figures here reflect the most recent verifiable public record as of August 2026, not necessarily the final word.

What Would Encryption Consulting Recommend?

The Kaseya attack is a certificate and trust problem as much as it is a patching problem. A fraudulently obtained signing certificate let a malicious update look legitimate, and a single compromised management tool propagated ransomware to thousands of endpoints automatically. Encryption Consulting works with MSPs and enterprises to close exactly that gap:

  • CodeSign Secure centralizes and monitors code-signing keys and certificates so a stolen or fraudulent signing identity cannot be used to distribute malware disguised as a trusted update.
  • HSM-as-a-Service keeps private keys, including signing keys, in FIPS 140-3 validated hardware rather than on a server an attacker can reach through a web application flaw.
  • PKI-as-a-Service and CertSecure Manager give MSPs and enterprises continuous visibility into every certificate in their environment, so an unauthorized or anomalous certificate is detected instead of trusted.
  • Encryption Advisory services help MSPs and enterprises build the segmentation, least-privilege access, and incident response runbooks this checklist calls for, backed by our ISO/IEC 27001:2022 and SOC 2 certified delivery practices.

Tailored Encryption Services

We assess, strategize & implement encryption strategies and solutions.

Conclusion

The Kaseya VSA attack was not the first supply chain ransomware incident, and it was not the last, but it remains one of the clearest public examples of what happens when a single trusted tool, a single certificate, and a single automatic update channel all fail at once. The technical fixes are well understood five years later: patch RMM tools on a real SLA, monitor and control code-signing certificates, segment management access, and keep tested offline backups. The harder work is making those controls routine before the next Kaseya-scale incident, not after it.

Frequently Asked Questions

What caused the Kaseya ransomware attack? The REvil ransomware group exploited an authentication bypass zero-day vulnerability, tracked as CVE-2021-30116, in Kaseya VSA’s web interface. That access let attackers run malicious code and push a fake update, signed with a fraudulently obtained certificate, through VSA’s own automatic update channel to MSPs and their downstream customers.

How many companies were affected by the Kaseya attack? Roughly 60 managed service providers were directly compromised. Public estimates of downstream businesses affected through those MSPs range from about 800 to 1,500, including Coop Sweden’s approximately 800 grocery stores, which closed for nearly a week.

Did Kaseya pay the ransom? No. Kaseya has stated publicly that it did not pay REvil’s $70 million ransom demand. A universal decryptor reached Kaseya through an unnamed trusted third party by July 22 to 23, 2021, and some later reporting indicated the FBI had obtained the same key earlier but withheld it during an active operation against REvil’s infrastructure.

Was anyone caught for the Kaseya attack? Yes. Ukrainian national Yaroslav Vasinskyi was arrested in Poland in October 2021, extradited to the United States in March 2022, and sentenced in May 2024 to 13 years and 7 months for his role in the Kaseya attack and other ransomware activity. Russia’s FSB separately detained 14 alleged REvil members in January 2022, though not every individual linked to the group has been prosecuted.

Is Kaseya VSA still safe to use today? Kaseya patched the specific vulnerabilities exploited in 2021 and has continued to update VSA since. The bigger, still-current lesson is not about Kaseya’s product specifically: any RMM, CI/CD, or automatic-update tool that holds broad administrative trust over many downstream systems is a high-value target, and organizations using any such tool should apply the remediation checklist above regardless of vendor.

References