Get 40% Off
🤯 This Tech Portfolio is up 29% YTD! Join Now to Get April’s Top PicksGet The Picks – Just 99 USD

Up to 1,500 businesses affected by ransomware attack, U.S. firm's CEO says

Published 07/05/2021, 08:21 AM
Updated 07/05/2021, 08:20 PM
© Reuters. FILE PHOTO: A man types on a computer keyboard in Warsaw in this February 28, 2013 illustration file picture.  REUTERS/Kacper Pempel/File Photo

© Reuters. FILE PHOTO: A man types on a computer keyboard in Warsaw in this February 28, 2013 illustration file picture. REUTERS/Kacper Pempel/File Photo

By Raphael Satter

WASHINGTON (Reuters) -Between 800 and 1,500 businesses around the world have been affected by a ransomware attack centered on U.S. information technology firm Kaseya, its chief executive said on Monday.

Fred Voccola, the Florida-based company's CEO, said in an interview that it was hard to estimate the precise impact of Friday's attack because those hit were mainly customers of Kaseya's customers.

Kaseya is a company which provides software tools to IT outsourcing shops: companies that typically handle back-office work for companies too small or modestly resourced to have their own tech departments.

One of those tools was subverted on Friday, allowing the hackers to paralyze hundreds of businesses on all five continents. Although most of those affected have been small concerns - like dentists' offices or accountants - the disruption has been felt more keenly in Sweden, where hundreds of supermarkets had to close because their cash registers were inoperative, or New Zealand, where schools and kindergartens were knocked offline.

The hackers who claimed responsibility for the breach have demanded $70 million to restore all the affected businesses' data, although they have indicated a willingness to temper their demands in private conversations with a cybersecurity expert and with Reuters.

"We are always ready to negotiate," a representative of the hackers told Reuters earlier Monday. The representative, who spoke via a chat interface on the hackers' website, didn't provide their name.

Voccola refused to say whether he was ready to take the hackers up on the offer.

"I can't comment 'yes,' 'no,' or 'maybe'," he said when asked whether his company would talk to or pay the hackers. "No comment on anything to do with negotiating with terrorists in any way."

The topic of ransom payments has become increasingly fraught as ransomware attacks become increasingly disruptive - and lucrative.

Voccola said he had spoken to officials at the White House, the Federal Bureau of Investigation, and the Department of Homeland Security about the breach but declined to say what they had told him about paying or negotiating.

On Sunday the White House said it was checking to see whether there was any "national risk" posed by ransomware outbreak but Voccola said that - so far - he was not aware of any nationally important organizations being hit.

"We're not looking at massive critical infrastructure," he said. "That's not our business. We're not running AT&T (NYSE:T)'s network or Verizon (NYSE:VZ)'s 911 system. Nothing like that."

Because Voccola's firm was in the process of fixing a vulnerability in the software that was exploited by the hackers when the ransomware attack was executed, some information security professionals have speculated that the hackers might've been monitoring his company's communications from the inside.

Voccola said neither he nor the investigators his company had brought in had seen any sign of that.

"We don't believe that they were in our network," he said. He added that the details of the breach would be made public "once its 'safe' and OK to do that."

Some experts believe the full fallout from the hack will come into focus on Tuesday, when Americans return from their July Fourth holiday weekend. Beyond the United States, the most notable disruption occurred in Sweden - where hundreds of Coop supermarkets had to shut their doors because their cash registers were inoperative - and in New Zealand, where 11 schools and several kindergartens were affected.

In their conversation with Reuters, the hackers' representative described the disruption in New Zealand as an "accident."

But they expressed no such regret about the disruption in Sweden.

© Reuters. A 3D printed model of a man working on a computer, LED lights and toy people figures are seen in front of displayed binary code and words

The supermarkets' closure was "nothing more than a business," the representative said.

About a dozen different countries have had organizations affected by the breach in some way, according to research published https://www.welivesecurity.com/2021/07/03/kaseya-supply-chain-attack-what-we-know-so-far by cybersecurity firm ESET.

Latest comments

An IT company manages computers for customer should take security seriously. Part of their job is to make sure all devices have malware protection. This is the result of talking customers money and do little or nothing.
Sounds like you're absolutely clueless about how the attacks work.  Which is okay, more proof IT isn't a dying profession.
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.