The Kaseya VSA attack: how one IT tool delivered ransomware to 1,500 businesses
On July 2, 2021, ransomware reached up to 1,500 small and medium-sized businesses in a single wave, delivered through the remote management tool their own IT providers used to look after them.[1] This case file covers how a known but still-open flaw in that tool was used, what the man convicted for it received, and the one control that would have limited the damage.
What happened
Kaseya sells VSA, software that managed service providers use to monitor, update and fix their clients' computers from a distance. One provider might use it to manage dozens of small offices, clinics or shops at once. That reach is what makes it useful, and what made it a target.[1]
On April 6, 2021, researchers at the Dutch Institute for Vulnerability Disclosure privately warned Kaseya about 7 serious vulnerabilities in VSA. Kaseya released fixes for some of them on April 10 and May 8.[1] Others, including one that could expose login credentials, were still open in early July.[1]
On Friday, July 2, the REvil ransomware operation used a still-unpatched flaw to take over on-premises VSA servers run by service providers and push ransomware out to the businesses those servers managed.[1][2] Kaseya shut down its cloud service and told customers to take their own VSA servers offline. Some providers were still waiting for working patches nearly 2 weeks later.[1]
How they got in
The attackers did not break into each victim separately. They went after the one tool that already had trusted, administrator-level access to all of them. Once they controlled a service provider's VSA server, the ransomware traveled down the same channel normally used to deliver software updates, so it arrived looking like routine maintenance.[1][2]
The entry point was a weakness in VSA itself, catalogued as CVE-2021-30116, that researchers had reported months earlier and that had not yet been fixed.[1] The victims, many of them small businesses, had no direct relationship with Kaseya at all. They simply relied on an IT provider that relied on Kaseya.
That chain of trust is what made the attack so efficient. A single compromise at the top reached roughly 1,500 organizations underneath it, most of which had never assessed, or even heard of, the software with the keys to their computers.[2]
What it cost
For the businesses hit, the cost was files encrypted, systems down and days or weeks of recovery during a holiday weekend in the United States. Kaseya's chief executive, Fred Voccola, publicly called the situation very disappointing and promised direct financial help to affected customers while the company delayed restarting its service to add security layers.[1]
One REvil affiliate was brought to justice. Yaroslav Vasinskyi, a Ukrainian national, was arrested in October 2021 while trying to enter Poland and extradited to the United States in March 2022.[2] He pleaded guilty to an 11-count indictment and on May 2, 2024, was sentenced to 13 years and 7 months in prison and ordered to pay $16 million in restitution.[2] Prosecutors tied him to more than 2,500 REvil attacks with total ransom demands of more than $700 million.[2] Authorities also seized about 39.9 bitcoin and $6.1 million.[2]
The missing control
The missing control: a risk assessment of vendor remote access. Thousands of businesses gave a remote management tool full control of their computers without knowing how it was secured or what would happen if it was compromised.
An assessment would have asked a few blunt questions. Which outside tools can install software on our machines? Are they patched quickly when flaws are reported? Can they reach every device, or only the ones they need? What is our plan if the provider's tool is hijacked? Businesses that limited the tool's reach, kept offline backups and knew how to cut it off quickly were far better placed when a flaw that had sat open for months was finally used.[1]
What to do in your business
- Ask your IT provider what tools they use. Get the names of the remote management and support tools that can reach your computers, and how quickly they apply security updates to them.
- Put it in the contract. Require your provider to protect their own tools with a second login factor, patch critical flaws promptly and tell you within a set time if they are breached.
- Limit what the tool can reach. If a system does not need remote management, such as a backup server, keep the tool off it.
- Keep an offline backup. Hold at least one copy of important data that no remote tool can reach or change, and test that you can restore it.
- Know how to pull the plug. Agree with your provider on how to disconnect their access fast in an emergency, and who on your side can ask for it.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.