On the afternoon of Friday, July 2, 2021, REvil ransomware began deploying through Kaseya VSA - a remote monitoring and management platform used by managed service providers to remotely manage their clients' computers. Because MSPs use Kaseya to manage thousands of endpoints each, every Kaseya-connected MSP that was compromised became a vector for infecting all of its clients simultaneously. By the time the US was waking up to a holiday weekend, between 800 and 1,500 businesses across 17 countries had been encrypted. It was the largest ransomware attack in history by number of victims.
Kaseya VSA and the MSP Attack Surface
Kaseya VSA is software that allows IT service providers to remotely monitor, manage, patch, and control computers for their clients. An MSP running Kaseya can push software, execute commands, and modify settings across thousands of endpoints from a single console. This is exactly what makes Kaseya valuable - and exactly what made it an ideal ransomware delivery mechanism. Compromise the platform and you compromise every client connected to it.
The attackers exploited CVE-2021-30116 and related vulnerabilities in the Kaseya VSA web interface - an authentication bypass and arbitrary file upload chain that allowed unauthenticated remote code execution. They had been researching these vulnerabilities for months. The Dutch Institute for Vulnerability Disclosure (DIVD) had actually been working with Kaseya on a coordinated disclosure of the same vulnerabilities when the attack occurred. Kaseya was in the process of preparing patches. REvil moved first.
The Scale
The victims ranged from Coop supermarkets in Sweden - which had to close 800 stores because their checkout systems were encrypted - to kindergartens in New Zealand, schools in New Zealand, and dentist offices in the United States. The attack's reach was a function of MSP structure: many small businesses outsource IT to an MSP, which manages dozens to hundreds of clients. A single MSP compromise multiplied into hundreds of downstream victims.
REvil initially demanded $70 million for a universal decryptor that would decrypt all affected systems. This was widely viewed as a negotiating anchor rather than a serious demand. REvil also approached individual victims and MSPs with tailored ransom demands ranging from $45,000 for individual businesses to $5 million for larger MSPs.
The Biden-Putin Call and REvil's Disappearance
The Kaseya attack came approximately three weeks after President Biden had met with President Putin in Geneva and explicitly warned that critical infrastructure cyberattacks would have consequences. The timing was politically radioactive. Biden publicly acknowledged the attack and stated that if it was confirmed to be Russia, there would be a response.
On July 13, 2021 - eleven days after the attack - REvil's infrastructure went dark. Their Tor-based leak site, payment portal, and negotiation portals all went offline simultaneously. No announcement was made. REvil simply vanished. The prevailing interpretation was that the group had been pressured or instructed to stand down by Russian authorities responding to Biden's warnings, possibly to avoid more severe consequences.
Kaseya subsequently obtained a universal decryptor and provided it to affected organizations without publicly disclosing how they obtained it. Later reporting indicated the FBI had obtained the decryptor from REvil's infrastructure before the group went offline and had been working with Kaseya to deploy it. The FBI's decision to withhold the decryptor for several weeks while investigating REvil - during which affected businesses remained encrypted - generated significant criticism.
REvil's Return and Arrest
REvil reappeared in September 2021 with restored infrastructure, suggesting the group's leadership had concluded the pressure had passed. The revival was short-lived. In October 2021, the FBI and international partners conducted a coordinated operation that compromised REvil's own infrastructure and took their servers offline for the second time. This time, several arrests followed.
In November 2021, the US Department of Justice indicted Yaroslav Vasinskyi, a 22-year-old Ukrainian national, for the Kaseya attack. Vasinskyi had crossed from Ukraine into Poland and was arrested. He was extradited to the United States and in May 2024 was sentenced to 13 years and 7 months in federal prison - one of the longest ransomware sentences to date. A Russian national, Yevgeniy Polyanin, was also indicted and remains a fugitive.
Lessons for Supply Chain Security
The Kaseya attack joined SolarWinds as the defining supply chain compromise events of 2020-2021. Both demonstrated the same principle: attacking through trusted software and service relationships rather than directly against targets. SolarWinds compromised a monitoring platform; Kaseya compromised an endpoint management platform. In both cases, the attack leveraged trust that downstream organizations placed in their software vendors or MSPs.
For the MSP industry, the attack forced a reckoning with the security of the platforms that MSPs relied on, and with the security practices of MSPs themselves. Many MSPs had connected their Kaseya VSA instances directly to the internet without additional authentication controls. The attack accelerated discussions about MSP security standards - a largely unregulated space where a single poorly-secured provider could expose hundreds of clients.