Case file · KASEYA 2021

The Kaseya VSA attack: how one IT tool delivered ransomware to 1,500 businesses

Published 2026-09-29 · 4 min read · Missing control: Vendor remote access risk assessment

On July 2, 2021, ransomware reached up to 1,500 small and medium-sized businesses in a single wave, delivered through the remote management tool their own IT providers used to look after them.[1] This case file covers how a known but still-open flaw in that tool was used, what the man convicted for it received, and the one control that would have limited the damage.

What happened

Kaseya sells VSA, software that managed service providers use to monitor, update and fix their clients' computers from a distance. One provider might use it to manage dozens of small offices, clinics or shops at once. That reach is what makes it useful, and what made it a target.[1]

On April 6, 2021, researchers at the Dutch Institute for Vulnerability Disclosure privately warned Kaseya about 7 serious vulnerabilities in VSA. Kaseya released fixes for some of them on April 10 and May 8.[1] Others, including one that could expose login credentials, were still open in early July.[1]

On Friday, July 2, the REvil ransomware operation used a still-unpatched flaw to take over on-premises VSA servers run by service providers and push ransomware out to the businesses those servers managed.[1][2] Kaseya shut down its cloud service and told customers to take their own VSA servers offline. Some providers were still waiting for working patches nearly 2 weeks later.[1]

How they got in

The attackers did not break into each victim separately. They went after the one tool that already had trusted, administrator-level access to all of them. Once they controlled a service provider's VSA server, the ransomware traveled down the same channel normally used to deliver software updates, so it arrived looking like routine maintenance.[1][2]

The entry point was a weakness in VSA itself, catalogued as CVE-2021-30116, that researchers had reported months earlier and that had not yet been fixed.[1] The victims, many of them small businesses, had no direct relationship with Kaseya at all. They simply relied on an IT provider that relied on Kaseya.

That chain of trust is what made the attack so efficient. A single compromise at the top reached roughly 1,500 organizations underneath it, most of which had never assessed, or even heard of, the software with the keys to their computers.[2]

What it cost

For the businesses hit, the cost was files encrypted, systems down and days or weeks of recovery during a holiday weekend in the United States. Kaseya's chief executive, Fred Voccola, publicly called the situation very disappointing and promised direct financial help to affected customers while the company delayed restarting its service to add security layers.[1]

One REvil affiliate was brought to justice. Yaroslav Vasinskyi, a Ukrainian national, was arrested in October 2021 while trying to enter Poland and extradited to the United States in March 2022.[2] He pleaded guilty to an 11-count indictment and on May 2, 2024, was sentenced to 13 years and 7 months in prison and ordered to pay $16 million in restitution.[2] Prosecutors tied him to more than 2,500 REvil attacks with total ransom demands of more than $700 million.[2] Authorities also seized about 39.9 bitcoin and $6.1 million.[2]

The missing control

The missing control: a risk assessment of vendor remote access. Thousands of businesses gave a remote management tool full control of their computers without knowing how it was secured or what would happen if it was compromised.

An assessment would have asked a few blunt questions. Which outside tools can install software on our machines? Are they patched quickly when flaws are reported? Can they reach every device, or only the ones they need? What is our plan if the provider's tool is hijacked? Businesses that limited the tool's reach, kept offline backups and knew how to cut it off quickly were far better placed when a flaw that had sat open for months was finally used.[1]

What to do in your business

Watch the case
One IT tool, fifteen hundred businesses hit at onceDrops 2026-12-14
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. SecureWorld: Kaseya's race to patch before the ransomware attack
  2. BleepingComputer: REvil hacker behind Kaseya ransomware attack gets 13 years in prison