On the afternoon of Friday, July 2, 2021, REvil ransomware began deploying through Kaseya VSA - a remote monitoring and management platform used by managed service providers to remotely manage their clients' computers. Because MSPs use Kaseya to manage thousands of endpoints each, every Kaseya-connected MSP that was compromised became a vector for infecting all of its clients simultaneously. By the time the US was waking up to a holiday weekend, between 800 and 1,500 businesses across 17 countries had been encrypted. It was the largest ransomware attack in history by number of victims.

Kaseya VSA and the MSP Attack Surface

Kaseya VSA is software that allows IT service providers to remotely monitor, manage, patch, and control computers for their clients. An MSP running Kaseya can push software, execute commands, and modify settings across thousands of endpoints from a single console. This is exactly what makes Kaseya valuable - and exactly what made it an ideal ransomware delivery mechanism. Compromise the platform and you compromise every client connected to it.

The attackers exploited CVE-2021-30116 and related vulnerabilities in the Kaseya VSA web interface - an authentication bypass and arbitrary file upload chain that allowed unauthenticated remote code execution. They had been researching these vulnerabilities for months. The Dutch Institute for Vulnerability Disclosure (DIVD) had actually been working with Kaseya on a coordinated disclosure of the same vulnerabilities when the attack occurred. Kaseya was in the process of preparing patches. REvil moved first.

[TECHNICAL NOTE]
The attack chain was technically elegant. REvil delivered a malicious update through the Kaseya VSA agent - the same mechanism MSPs used to legitimately push software. The ransomware payload was disguised as a Kaseya software update and signed with a legitimate-looking certificate. Because Kaseya agents run with high privileges (they need them to manage systems), the ransomware executed with SYSTEM-level access. Security software that might otherwise detect ransomware was explicitly excluded from scanning via the Kaseya agent's own exclusion lists.

The Scale

The victims ranged from Coop supermarkets in Sweden - which had to close 800 stores because their checkout systems were encrypted - to kindergartens in New Zealand, schools in New Zealand, and dentist offices in the United States. The attack's reach was a function of MSP structure: many small businesses outsource IT to an MSP, which manages dozens to hundreds of clients. A single MSP compromise multiplied into hundreds of downstream victims.

REvil initially demanded $70 million for a universal decryptor that would decrypt all affected systems. This was widely viewed as a negotiating anchor rather than a serious demand. REvil also approached individual victims and MSPs with tailored ransom demands ranging from $45,000 for individual businesses to $5 million for larger MSPs.

The Biden-Putin Call and REvil's Disappearance

The Kaseya attack came approximately three weeks after President Biden had met with President Putin in Geneva and explicitly warned that critical infrastructure cyberattacks would have consequences. The timing was politically radioactive. Biden publicly acknowledged the attack and stated that if it was confirmed to be Russia, there would be a response.

On July 13, 2021 - eleven days after the attack - REvil's infrastructure went dark. Their Tor-based leak site, payment portal, and negotiation portals all went offline simultaneously. No announcement was made. REvil simply vanished. The prevailing interpretation was that the group had been pressured or instructed to stand down by Russian authorities responding to Biden's warnings, possibly to avoid more severe consequences.

Kaseya subsequently obtained a universal decryptor and provided it to affected organizations without publicly disclosing how they obtained it. Later reporting indicated the FBI had obtained the decryptor from REvil's infrastructure before the group went offline and had been working with Kaseya to deploy it. The FBI's decision to withhold the decryptor for several weeks while investigating REvil - during which affected businesses remained encrypted - generated significant criticism.

[WARNING]
The FBI's decision to hold the Kaseya decryptor was controversial and subsequently disclosed by the Washington Post. The FBI withheld the key for approximately three weeks while conducting an operation targeting REvil's infrastructure - during which 1,500 businesses remained encrypted and unable to operate. When REvil disappeared and the operation became moot, the FBI provided the decryptor. The incident raised fundamental questions about law enforcement priorities versus victim assistance in ransomware cases: should the government withhold tools that could immediately help victims in order to pursue criminal prosecutions?

REvil's Return and Arrest

REvil reappeared in September 2021 with restored infrastructure, suggesting the group's leadership had concluded the pressure had passed. The revival was short-lived. In October 2021, the FBI and international partners conducted a coordinated operation that compromised REvil's own infrastructure and took their servers offline for the second time. This time, several arrests followed.

In November 2021, the US Department of Justice indicted Yaroslav Vasinskyi, a 22-year-old Ukrainian national, for the Kaseya attack. Vasinskyi had crossed from Ukraine into Poland and was arrested. He was extradited to the United States and in May 2024 was sentenced to 13 years and 7 months in federal prison - one of the longest ransomware sentences to date. A Russian national, Yevgeniy Polyanin, was also indicted and remains a fugitive.

Lessons for Supply Chain Security

The Kaseya attack joined SolarWinds as the defining supply chain compromise events of 2020-2021. Both demonstrated the same principle: attacking through trusted software and service relationships rather than directly against targets. SolarWinds compromised a monitoring platform; Kaseya compromised an endpoint management platform. In both cases, the attack leveraged trust that downstream organizations placed in their software vendors or MSPs.

For the MSP industry, the attack forced a reckoning with the security of the platforms that MSPs relied on, and with the security practices of MSPs themselves. Many MSPs had connected their Kaseya VSA instances directly to the internet without additional authentication controls. The attack accelerated discussions about MSP security standards - a largely unregulated space where a single poorly-secured provider could expose hundreds of clients.