Get 40% Off
⚠ Earnings Alert! Which stocks are poised to surge?
See the stocks on our ProPicks radar. These strategies gained 19.7% year-to-date.
Unlock full list

Ransomware breach at Florida IT firm hits 200 businesses

Published 07/02/2021, 06:05 PM
Updated 07/02/2021, 09:30 PM
© Reuters. Computer network equipment is seen in a server room in Vienna, Austria, October 25, 2018. REUTERS/Heinz-Peter Bader

By Raphael Satter and Joseph Menn

WASHINGTON (Reuters) -Hundreds of American businesses were hit Friday by an unusually sophisticated ransomware attack that hijacked widely used technology management software from a Miami-based supplier called Kaseya.

The attackers changed a Kaseya tool called VSA, used by companies that manage technology at smaller businesses. They then encrypted the files of those providers' customers simultaneously.

Security firm Huntress said it was tracking eight managed service providers that had been used to infect some 200 clients.

Kaseya said on its own website that it was investigating a "potential attack" on VSA, which is used by IT professionals to manage servers, desktops, network devices and printers.

It said it shut down some of its infrastructure in response and that it was urging customers that used VSA on their premises to immediately turn off their servers.

"This is a colossal and devastating supply chain attack," Huntress senior security researcher John Hammond said in an email, referring to an increasingly high profile hacker technique of hijacking one piece of software to compromise hundreds or thousands of users at a time.

Hammond added that because Kaseya is plugged in to everything from large enterprises to small companies "it has the potential to spread to any size or scale business." Many managed service providers use VSA, although their customers may not realize it, experts said.

Some employees at service providers said on discussion boards that their clients had been hit before they could get a warning to them.

Reuters was not able to reach a Kaseya representative for further comment. Huntress said it believed the Russia-linked REvil ransomware gang - the same group of actors blamed by the FBI for paralyzing meat packer JBS last month - was to blame for the latest ransomware outbreak.

DEMANDS FOR RANSOM

A private security executive working on the response effort said that ransom demands accompanying the encryption ranged from a few thousand dollars to $5 million or more.

The corruption of an update process shows a marked escalation in sophistication from most ransomware attacks, which take advantage of security loopholes such as common passwords without two-factor authentication.

An email sent to the hackers seeking comment was not immediately returned. In a statement, the U.S. Cybersecurity and Infrastructure Security Agency said it was "taking action to understand and address the recent supply-chain ransomware attack" against Kaseya's VSA product.

© Reuters. Computer network equipment is seen in a server room in Vienna, Austria, October 25, 2018. REUTERS/Heinz-Peter Bader

Supply chain attacks have crept to the top of the cybersecurity agenda after the United States accused hackers of operating at the Russian government's direction and tampering with a network monitoring tool built by Texas software firm SolarWinds.

Kaseya has 40,000 customers for its products, though not all use the affected tool.

Latest comments

could be false flag
could be false flag just scape ghost on Russia
Russian mafia is running the Russian government with Putin at its head. Putin is getting a piece of the action. Putin must be making a fortune and making the Biden look weak and foolish. Putin is a dictator and will lie cheat and steal if he thinks he can get away with it. he's ripped off the Russian people for 10s of billions of rubles. Putin is a corrupt, bloodthirsty psycopath he needs to be "neutralized".
why not blame China🤔
Biden IS weak and foolish.
Alleged is right? They could be anybody, from anywhere. blaming the Russians for stuff goes back long, long time. I have know way of knowing what I read, or hear on the boobtube is true, or not.
You are right. In places in Texas and Florida, it's likely actors in the companies themselves.
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.