What is Kaseya Ransomware Attack?

Ransomware attacks are increasing at an alarming rate, and it is a rapidly evolving trend worldwide. According to the BitSight Ransomware Analysis report, approximately 80 ransomware attack incidents have happened every month since the year 2021 began. It has been noted repeatedly that cybercriminals are now equipped with sophisticated technology and tools and use multifaceted tactics like phishing and ransomware to exploit vulnerabilities. Given the current cyber threat scenario, the Kaseya ransomware attack is not surprising at all. Find out everything you need to know about the incident which is touted as the biggest ransomware attack on record. 

Who is Kaseya?

Kasey is an IT solutions company with its international headquarters situated in Dublin, Ireland. Additionally, the company has headquarters located in Miami, Florida and maintains its presence in other 10 countries worldwide. It provides software solutions that help businesses to manage their networks. 

One of its solutions Virtual Systems/Server Administrator (VSA) combines management and remote-monitoring tool for managing networks and endpoints and it is hosted in the cloud. Their software is developed for Managed or Shared Service Providers (MSP) and enterprises. It is used to send software updates to systems on networks. And according to Kaseya, more than 40, 000 organizations across the globe use a minimum of one software solution from them. 

What is a Ransomware Attack?

Before moving forward, you need to know what a ransomware attack is. Ransomware has become one of the most dangerous methods used by cybercriminals to disrupt and cause serious damage to modern businesses. It is a kind of malware that can encrypt files. Thus, attackers infiltrate systems or networks using ransomware and lock valuable files containing sensitive information. In most cases, the attackers ask for a ransom in return for a decryption key. If the ransom is not paid, the information is either sold or leaked online. 

Ransomware Attack on Kaseya

On July 2, the news of a potential ransomware attack on the VSA came to the fore, which was believed to have affected a small number of on-premise customers. The company revealed the news and cautioned its customers to shut off the VSA servers.

By July 4, on further investigation, it was revealed that the security incident was more severe than what was believed earlier. It was established that the Kaseya ransomware incident is a sophisticated attack. 

It is now known that hackers exploited several vulnerabilities in the software to drop ransomware, and it was further escalated to affecting multiple MSPs and their respective customers. More specifically, the experts claim that it was the case of authentication bypass vulnerability that enabled threat actors to find a way around controls, achieve authenticated sessions, drop malicious payload and execute the attack. 

Who conducted the Ransomware Attack on Kaseya?

REvil or Sodinikibi is a ransomware group that has claimed responsibility for the cyberattack carried out against Kaseya. Over the weekend, the group is believed to have claimed to infect more than a million systems. Moreover, it has asked for a ransom of 70 million dollars in bitcoin cryptocurrency to offer the decryption key. The group is known for conducting such ransomware attacks in the past. 

The Impact

To put it simply, the REvil group infiltrated Kaseya, and now has access to their extensive customer’s data. It is now estimated that cybercriminals behind the attack were able to conduct a supply-chain attack, harming 70 of the immediate customers initially who are MSPs. But one of the major concerns is that most of those affected down the chain are small to medium businesses that depend on Kaseya’s managed service providers for the security of their systems. They are close to 350 organizations. 

On July 5, Kaseya spokesperson revealed that small and medium-size companies, between 800 to 1500, are impacted. They also claimed that the SaaS customers were not compromised. However, independent researchers think otherwise and have put the figure at approximately 2000. The disruption has massively spread across the globe with hundreds of Swedish supermarkets closed and schools and kindergartens in New Zealand affected. This is the reason why experts believe it is one of the farthest-reaching ransomware attacks of all time. 

The Next Move

As per Reuters, Kaseya’s CEO, Fred Voccola, has not confirmed whether they are willing to pay the ransom. However, he said: “No comment on anything to do with negotiating with terrorists in any way.” It indicates that paying attackers is out of the question. Experts also agree that hackers, if paid, are going to escalate and promote such practices and it will get worse in the future. 

The matter has captured the attention of the upper echelons of the White House in the US, and President Joe Biden has ordered an inquiry to look into the incident. Moreover, the Federal Bureau of Investigation (FBI) and US Cybersecurity and Infrastructure Security Agency (CISA) have been briefed about the incident by the company as well. FBI has released a statement on the Kaseya Ransomware Attack and has recommended mitigations. You can find the details here: https://www.ic3.gov/Media/News/2021/210706.pdf.

Meanwhile, Kaseya is putting in the restoration efforts with additional security improvements, configuration changes and much more. However, as of July 8, the recovery is believed to be taking longer than expected. 

Cybersecurity Advice

To protect your business against ransomware attacks, it is high time that you follow the often-repeated strategy of installing the latest updates, educating and training employees and partnering with cybersecurity professionals who can test your security status frequently and develop robust defence mechanisms against such attacks. 

Many of the cybersecurity compromises occur due to human error. Thus, leaders, managers and employees should have good knowledge about cyber threats. There has to be a responsible person who constantly keeps a tab on software used in the companies and their update status. Finally, the cybersecurity experts, engineers and managers should develop a comprehensive strategy that covers all business assets at all times. It should be a daily task to analyze logs, network traffic and look for any indicator that may signal a compromise. Additionally, companies should allocate more budgets to use the latest technology and tools to prevent such sophisticated attacks. 

Cyber attacks are a menace to businesses today, and they will continue in future as well. Every business must consider the threat actors and their potential to cause irreversible damage. It is high time leaders understand cyber attacks as technical as well as a business problem. Therefore, necessary action and partnership with professional cybersecurity team must be a priority for a safe and secure future for all businesses.