// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Kaseya

DISCLOSED 2021-07-02 · SUPPLY CHAIN · RANSOMWARE

Kaseya suffered a major ransomware attack via its VSA remote management software, impacting up to 1,500 downstream businesses. The REvil group exploited zero-day vulnerabilities to push a malicious update, demanding a $70 million ransom. The attack is considered one of the largest supply-chain ransomware incidents in history.

The record

What we know

Disclosed
2021-07-02
Attack vector
Supply Chain
Sector
IT Services
Country
US
Domain
kaseya.com
RANSOMWARE ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · would prevent · opinion

A positive-security model that only allows authorized changes could have blocked the unauthorized deployment of ransomware via the VSA agent, as the malicious update would be rejected.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other supply chain breaches on file

This page is the permanent ColdRecon entry for the Kaseya disclosure. It updates if new public reporting emerges. All tracked breaches →

Kaseya just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →