KASEYA

Vendor / institutional-failure dossier Event: Jul 2, 2021 Status: operating

The remote-management tool a criminal gang turned into a delivery truck. On a July 4th holiday weekend, REvil rode Kaseya's VSA software down through the managed-service-provider supply chain into as many as 1,500 downstream businesses — and shut 800 Swedish grocery stores. Kaseya was the victim of the crime. Whether it was also warned first is the argument — and there are receipts on both sides.

I am proud to report that our team had a plan in place to jump into action and executed that plan perfectly today.

CEO Fred Voccola, in Kaseya's official incident statement, 10:00 PM EDT, July 2, 2021 — Kaseya, "Important Notice" / incident overview

Kaseya did not pay a ransom – either directly or indirectly through a third party – to obtain the decryptor.

Kaseya's official statement, July 26, 2021 — Kaseya incident overview

ENTITY
Kaseya Limited, Miami, Florida — IT-management software; its VSA (Virtual System Administrator) is a remote-monitoring-and-management tool used by managed service providers FACT
PRINCIPAL
Fred Voccola, CEO — the company's public voice through the incident; the record below is the company's conduct FACT
THE EVENT
July 2, 2021 — the REvil / Sodinokibi gang exploited zero-day vulnerabilities in on-premises VSA servers to push ransomware through MSPs to their customers; between 800 and 1,500 downstream businesses hit FACT
THE DRAMA
A coordinated-disclosure clock (DIVD, reported April 6, 2021) and a separate ex-employee "warnings ignored" account — set against a fast, coordinated victim response, a free universal decryptor, and no ransom paid
RECORD
Kaseya was the victim of a criminal attack; the attackers, not Kaseya, did the harm. No finding of negligence or fraud against the company appears in this record. The "ignored warnings" account is attributed reporting, not adjudication. FACT
STATUS
OPERATINGkaseya.com is live; VSA remains a shipping product

Read this one carefully, because it is not the usual specimen. Most files here are about someone selling something that does not work. This is about a company whose product did work — well enough that a ransomware crew borrowed it to reach fifteen hundred businesses at once. The crime was REvil's. Keep that fixed; this file does.

What is in dispute is narrower and older: whether Kaseya was told, and when, and by whom — and whether "we were breached by a sophisticated adversary" and "we were warned and shipped it anyway" can both be true at the same time. Both sides get the microphone. Every beat carries its receipt. You decide.

the drama timeline

ACT I — THE WARNINGS (2017–APR 2021)

A supply-chain attack has a long fuse. Two separate clocks were already running before REvil arrived: one inside the building, one outside it. Only one of them is documented on a public case file.

  1. 2017–2020

    The internal account

    Bloomberg reports that, on several occasions from 2017 to 2020, Kaseya staff flagged wide-ranging cybersecurity concerns to company leaders that, the outlet writes, "often weren't fully addressed." Per the account of five former employees, complaints cited old code, weak encryption, and inconsistent patching; one ex-employee says he was fired about two weeks after sending executives a 40-page security briefing. This is those former employees' account, as reported — not an adjudicated finding, and Kaseya is not on record admitting it.

    Attributed, unadjudicated, and load-bearing to the "charlatan" angle — which is exactly why it wears its source in the open and carries no verdict.

  2. APR 6, 2021

    The coordinated-disclosure clock

    The Dutch Institute for Vulnerability Disclosure (DIVD) privately reports seven vulnerabilities in VSA to Kaseya and opens case DIVD-2021-00011. Over the following weeks Kaseya ships patches — v9.5.5 (Apr 10), v9.5.6 (May 8) — and on June 26 releases 9.5.7 to its SaaS environment, resolving CVE-2021-30116, the credential/authentication flaw later used in the attack. The catch: the fix for on-premises VSA servers — the ones REvil actually hit — was still in preparation when the attack came.

    The single fact that makes this hard: the exploited flaw was a reported flaw, patched on the SaaS side days before — and not yet on the on-prem side. Diligence and exposure in the same sentence.

ACT II — THE HOLIDAY WEEKEND (JUL 2–5, 2021)

Ransomware crews prefer long weekends, when the defenders are at barbecues. This one was timed to the Friday before July 4th. What follows is the fast part.

  1. JUL 2, 2021

    REvil rides the RMM

    The REvil / Sodinokibi gang exploits VSA zero-days to push ransomware through managed service providers to their downstream customers. Kaseya shuts down its SaaS servers within roughly an hour as a precaution and tells on-premises customers to shut down their VSA servers immediately. Voccola's same-day statement: the team "executed that plan perfectly today."

  2. JUL 2, 2021

    CISA lights the beacon

    CISA issues an alert the same day: it "is taking action to understand and address the recent supply-chain ransomware attack against Kaseya VSA and the multiple managed service providers (MSPs) that employ VSA software," and "encourages organizations to review the Kaseya advisory and immediately follow their guidance to shutdown VSA servers." A follow-on CISA–FBI guidance page for affected MSPs follows.

  3. JUL 5, 2021

    The blast radius, and the $70 million line

    Kaseya says between 800 and 1,500 downstream businesses were impacted. Sweden's Coop supermarket chain has to close roughly 800 stores for nearly a week — its point-of-sale ran through an affected MSP — "some in small villages without any other food shop." REvil posts its offer: a universal decryptor for every victim at once, for $70 million in Bitcoin.

ACT III — THE DECRYPTOR (JUL–SEP 2021)

Every ransomware story ends with a key. The interesting question is always who had it, and how long they sat on it.

  1. JUL 22–23, 2021

    A key from a "trusted third party"

    Kaseya announces it has obtained a universal decryptor from a "trusted third party" and is distributing it to victims free of charge; it later confirms the tool is effective and states plainly that it paid no ransom. By this point roughly three weeks have passed since the July 2 attack.

  2. SEP 2021

    The key was the FBI's — and it waited

    The Washington Post reports, per the sourced record, that the master key had come from the FBI, which had covertly obtained it earlier and held it for about three weeks before it reached victims — a delay the Bureau later said reflected an operation to take down REvil's infrastructure. The controversy here belongs to the government, not to Kaseya; it is included because it is part of how the story actually ended.

  3. EPILOGUE

    Still shipping

    kaseya.com is live and VSA remains a product. No negligence or fraud finding against Kaseya sits in this record. The DIVD case file remains public; the ex-employees' account remains their account; the fifteen hundred businesses remain in the past tense. The archive keeps the tape running.

both sides, on the record

The single point of failure: a remote-management tool that reaches thousands of downstream machines is, by design, a master key — and when it was compromised, the blast radius was 800 to 1,500 businesses and 800 shuttered stores in one weekend [6] [7].

The documented clock: DIVD reported the exploited authentication flaw (CVE-2021-30116) among seven vulnerabilities on April 6, 2021; the on-premises fix — for the servers actually attacked — had not shipped when REvil struck on July 2 [5].

The attributed account: per Bloomberg, five former employees say cybersecurity concerns raised from 2017 to 2020 — old code, weak encryption, inconsistent patching — were not fully addressed, and that VSA had been abused to spread ransomware before. That is their account, stated as theirs [8] [9].

Kaseya was the victim of a crime: the harm was done by REvil, a sophisticated criminal group exploiting zero-day vulnerabilities. Attribution of the attack is not in dispute, and nothing in this record finds Kaseya legally negligent, let alone fraudulent [1] [6].

It was already doing the right thing on disclosure: Kaseya was engaged in DIVD's coordinated-disclosure process, shipped multiple patches across April–June, and had pushed the SaaS fix for the exploited flaw days before the attack — the on-prem patch was in flight, not ignored [5].

The response was fast and cooperative: SaaS shut down within about an hour; on-prem customers told to shut down immediately; FBI, CISA, and Mandiant engaged; a universal decryptor obtained and given to victims free; and, in the company's own words, no ransom paid [2] [3] [4].

Scope of the record: the ex-employee "warnings ignored" account is attributed reporting from five unnamed-to-us former staff, unadjudicated and not admitted by the company; it never carries this page alone, and no motive is assigned to anyone at Kaseya [8].

YOU DECIDE

Scoped to the claims, never the company. The claim "Kaseya committed the harm" is false on the record — REvil did, exploiting a criminal zero-day, and there is no negligence or fraud finding here. The claim "Kaseya was warned and shipped anyway" is where it gets uncomfortable: the documented DIVD clock shows the exploited flaw was reported in April and not fully patched across the install base by July, and the ex-employee account — theirs, attributed, unadjudicated — says the culture that produced that gap went back years. Both of those can be true without making Kaseya the criminal. That is the whole difficulty, and it stays on the page at full strength.

Weigh the costly signals honestly: Kaseya spent the response ledger the way a diligent victim does — shut down in an hour, called the FBI, gave the decryptor away, paid no ransom. What it cannot buy back is the three months between "you have a hole" and "the hole was used." The single point of failure was working as designed the day it failed.

The archive does not judge. The archive merely keeps the tape running.

evidence locker

PRIMARY RECORD — GOVERNMENT, FIRST-PARTY, DISCLOSURE

  1. CISA — "Kaseya VSA Supply-Chain Ransomware Attack" alert (Jul 2, 2021) FACT — the agency confirming the attack and urging customers to shut down VSA servers, in its own words. cisa.gov/news-events/alerts/2021/07/02/kaseya-vsa-supply-chain-ransomware-attack
  2. CISA / FBI — guidance for affected MSPs and their customers FACT — the government's remediation guidance for the supply chain. cisa.gov/news-events/news/kaseya-ransomware-attack-guidance-affected-msps-and-their-customers
  3. Kaseya — incident overview / "Important Notice" SELF-PUBLISHED — Voccola's statements, the response timeline, the free decryptor, and the "no ransom paid" line, in the company's own words. kaseya.com/potential-attack-on-kaseya-vsa/
  4. Kaseya Helpdesk — incident update log SELF-PUBLISHED — the running technical updates to customers. helpdesk.kaseya.com/hc/en-gb/articles/4403440684689
  5. DIVD CSIRT — case DIVD-2021-00011, Kaseya VSA vulnerabilities (full disclosure) FACT — the coordinated-disclosure timeline: seven vulnerabilities reported Apr 6, patch dates, and the June 26 SaaS fix for CVE-2021-30116. csirt.divd.nl/cases/DIVD-2021-00011/

PRESS & RESEARCH

  1. Wikipedia — "Kaseya VSA ransomware attack" (sourced) FACT — the 800–1,500 scope, the Coop store closures, the $70M demand, and the FBI-held-key reporting, each with its own citation. en.wikipedia.org/wiki/Kaseya_VSA_ransomware_attack
  2. CNN — "Up to 1,500 businesses affected by ransomware attack" (Jul 2021) FACT — the downstream blast radius, contemporaneously. cnn.com/2021/07/06/tech/kaseya-ransomware-attack-businesses-affected/
  3. Bloomberg — "Kaseya Failed to Address Security Before Hack, Ex-Employees Say" (Jul 10, 2021) ATTRIBUTED — the five-former-employees account of warnings raised 2017–2020. Their account, as reported; unadjudicated. bloomberg.com/news/articles/2021-07-10/kaseya-failed-to-address-security-before-hack-ex-employees-say
  4. Engadget — "Kaseya was warned about security flaws years ahead of ransomware attack" ATTRIBUTED — corroborating summary of the Bloomberg reporting. engadget.com/kaseya-warned-of-security-flaws-before-ransomware-210226358.html
  5. Gizmodo — "Kaseya's Staff Sounded the Alarm About Security Flaws for Years" ATTRIBUTED — further secondary coverage of the ex-employee account. gizmodo.com/kaseyas-staff-sounded-the-alarm-about-security-flaws-fo-1847270346
  6. BankInfoSecurity — "Kaseya Vulnerabilities Were First Spotted in April" FACT — independent confirmation of the April disclosure window. bankinfosecurity.com/kaseya-vulnerabilities-first-spotted-in-april-a-17006
  7. ODNI / NCSC — "Kaseya VSA Supply Chain Ransomware Attack" summary (PDF) FACT — the U.S. counterintelligence summary of the incident. dni.gov/files/NCSC/documents/SafeguardingOurFuture/Kaseya….pdf
The standard. Everything above is sourced to a government alert, the company's own incident statements, a public coordinated-disclosure case file, and named press and research. Facts are stated as facts; the attack and its attribution to REvil are documented, and Kaseya's status as the victim of that crime is stated plainly and at full strength. The one contested claim — that Kaseya was warned about its own security and did not act — is split into what is documented (the DIVD clock) and what is attributed (the ex-employee account, credited to Bloomberg and stated as those employees' account, never adopted as our voice and never carrying the page alone). No negligence is asserted, no fraud is alleged, no motive is assigned. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.