Kaseya VSA / REvil - Authentication Bypass in an RMM Server → Ransomware Pushed as a Software Update → ~1,500 Businesses Encrypted Through Their IT Provider
On July 2, 2021, timed for the US Independence Day weekend when staffing was thinnest, REvil affiliates exploited zero-day vulnerabilities in on-premises Kaseya VSA servers - CVE-2021-30116 among them, an authentication bypass and credential disclosure flaw - and used the product's own agent update mechanism to push ransomware downstream. Kaseya VSA is remote monitoring and management software used by managed service providers to administer their clients' estates, so the encryptor arrived on victim machines as a trusted update from the company that manages their IT. Around 50 to 60 MSPs were compromised, and roughly 1,500 downstream businesses were encrypted. Sweden's Coop closed some 800 supermarkets because its point-of-sale system was administered by an affected provider. REvil demanded $70 million for a universal decryptor. The vulnerabilities were already known to Kaseya: the Dutch Institute for Vulnerability Disclosure had reported them and a patch was in development when the attack landed.
VSA servers are exposed by design - MSP technicians need to reach them, and so do the agents on every managed endpoint. That makes the management server a uniquely attractive target: it is reachable, it is authoritative over thousands of machines, and compromising it requires no lateral movement at all. The chain used included CVE-2021-30116, which allowed credential disclosure via the default download page and authentication bypass on versions before 9.5.7. Timing was chosen deliberately for the Friday before the July 4 weekend, when the people who would notice were least likely to be at a keyboard - a pattern worth planning around rather than being surprised by.
Vulnerabilities: Authentication bypass and credential disclosure, including CVE-2021-30116
Affected versions: Before 9.5.7
Timing: July 2, the Friday before the US Independence Day weekend
Why the management server: Reachable, authoritative over thousands of endpoints, no lateral movement needed
Nothing had to be smuggled past anything. RMM software exists to run arbitrary code on managed machines with high privilege - that is the product - so an attacker holding the server inherits precisely that capability, delivered through the channel every endpoint is configured to trust. The payload also arrived with the trust properties of legitimate management traffic, and the deployment included steps to hinder endpoint protection. Read this next to 3CX and the shared property is stark: when the distribution channel itself is compromised, the receiving end has no signal to work with, because everything about the delivery is exactly as it should be.
Privilege: Whatever the RMM agent runs as - typically full administrative rights
Endpoint view: A trusted management action from the expected server
Accompanying steps: Interference with endpoint protection during deployment
Shared property with 3CX: A compromised distribution channel leaves the receiver no signal
The amplification is the whole point of targeting an MSP. Compromising one VSA server reaches every client that provider administers, so 50 to 60 compromises produced roughly 1,500 encrypted businesses - a leverage ratio no direct campaign achieves. Coop Sweden is the clearest illustration of how far the blast travels: the grocery chain had no relationship with Kaseya at all, but its point-of-sale system was administered by an affected provider, and around 800 stores could not take payment and closed. Small businesses were hit hardest, because the entire reason they use an MSP is that they have no internal IT capability - so the compromise arrived through their only source of help, and removed it at the same moment.
Encrypted downstream: ~1,500 businesses
Third-order victim: Coop Sweden, ~800 stores closed - no relationship with Kaseya
Leverage: One management server reaches every client that provider administers
Worst affected: Small businesses whose only IT capability was the compromised provider
This is not a case of a defender who could not have known. DIVD researchers had found and reported the flaws, Kaseya was working on fixes, and the attack arrived inside the remediation window. That is a genuinely hard problem rather than a simple failure - disclosure timelines exist precisely because patches take time to build and test, and there is no version of this where the vendor moves instantly. But it does make one thing concrete for defenders: the gap between "reported" and "patched everywhere" is a period of real exposure for internet-facing management software, and the mitigation available during it is compensating controls - taking the console off the public internet, restricting source addresses, monitoring it closely - rather than waiting.
Status at time of attack: Patch in development
Patch released: July 11-12, 2021, roughly ten days after the attack
The general problem: The window between disclosure and deployment is real exposure
What is available in that window: Compensating controls, not patience
The $70 million universal-decryptor demand was a pricing decision as much as an extortion one: at that scale, negotiating individually with 1,500 businesses is operationally impossible, so the crew offered a single transaction instead. It was not paid. The FBI obtained the decryption key, and Kaseya was able to distribute a universal decryptor to affected customers later in July - though the FBI's decision to hold the key for a period while pursuing the actors, rather than releasing it immediately, drew sustained criticism from victims still down. REvil's infrastructure went offline days after the attack and the group was subsequently disrupted. For most victims none of that mattered in the moment: recovery depended on their own backups, and the businesses that recovered fastest were the ones that had tested restoring from them.
Resolution: The FBI obtained the key; Kaseya distributed a decryptor later in July
Contested: The delay between obtaining the key and releasing it to victims
Aftermath: REvil infrastructure went offline; the group was later disrupted
What actually determined recovery time: Whether the victim had tested backup restores
