EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/supply-chain-attack/kaseya-revil-2021
180/430

File EL-0251CriticalResolvedSupply Chain Attack / Ransomware Attack

Kaseya VSA REvil Ransomware Supply Chain Attack

Also filed as REvil Supply Chain Attack · Sodinokibi Attack · Kaseya VSA Breach

This incident involved the deployment of the REvil ransomware through a compromised Kaseya VSA (Virtual System Administrator) product. The attack leveraged a supply chain vulnerability, allowing the threat actors to simultaneously compromise hundreds of downstream Managed Service Provider (MSP) clients. The ransomware encrypted critical systems, causing widespread operational disruption across multiple sectors globally.

  • #revil
  • #sodinokibi
  • #kaseya
  • #vsa
  • #ransomware
  • #supply-chain
  • #critical-infrastructure
Notoriety9/10
Event
2 Jul 2021
Disclosed
2 Jul 2021
Target
Kaseya
Actor
REvil
Status
Resolved

01Summary

The attack, which occurred on July 2, 2021, was a highly coordinated ransomware campaign targeting the Managed Service Provider (MSP) industry. REvil, also known as Sodinokibi, exploited a vulnerability or weakness within Kaseya's VSA product, which is used by MSPs to manage client networks remotely. By compromising this single point of failure, the attackers gained access to the networks of numerous downstream clients, effectively turning Kaseya's product into a vector for mass infection. The ransomware payload encrypted data and demanded a ransom payment in cryptocurrency. The scale of the attack was massive, affecting over 1,500 distinct businesses and critical infrastructure components, leading to significant operational paralysis and forcing many victims to pay ransoms or undergo costly recovery efforts.

02Background

The Managed Service Provider (MSP) industry relies heavily on centralized tools like Kaseya VSA to manage diverse client environments. This reliance creates a single, high-value target for threat actors. Historically, supply chain attacks have targeted trusted third parties to maximize impact, and the MSP sector was identified as a prime target due to its interconnected nature and the critical services it provides.

03Key revelations

  1. 01The attack demonstrated the extreme vulnerability of the Managed Service Provider (MSP) model.
  2. 02The simultaneous compromise of over 1,500 distinct, unrelated businesses via a single vendor product.
  3. 03The high degree of coordination and professional execution characteristic of major ransomware syndicates.

04Technical analysis

The attack vector was the Kaseya VSA product itself. REvil utilized the compromised VSA to execute the ransomware payload across multiple client endpoints. The ransomware was designed to propagate rapidly and efficiently across networked systems, indicating a high level of operational security and pre-planning by the threat group. The attack demonstrated sophisticated lateral movement capabilities, bypassing standard network segmentation measures within the compromised MSP environment.

Attack vector
Supply Chain Compromise (Kaseya VSA product)
Attack method
Ransomware Deployment via Compromised Third-Party Tool
Initial access
Compromised Managed Service Tool (Kaseya VSA)
Lateral movement
Network Propagation via MSP Management Tools
Persistence
Ransomware Payload Execution
Exfiltration
Unknown (Likely data exfiltration prior to encryption)
Tool / malware
REvil
Malware family
REvil
Malware type
Ransomware

Vulnerabilities exploited

  • Kaseya VSA Vulnerability (Specific CVE not universally cited, but related to remote access/management)

MITRE ATT&CK techniques

  • T1566.001
  • T1071.001
  • T1486

05Threat actor

REvil (Sodinokibi) is a highly sophisticated, financially motivated ransomware group known for its aggressive tactics and high success rate. They specialize in exploiting vulnerabilities in widely used enterprise software and targeting critical infrastructure, demanding large ransoms paid in cryptocurrency.

Aliases

  • Sodinokibi

MITRE groups

  • TA0011
  • TA0003

Attribution sources

  • Mandiant
  • CrowdStrike
  • CISA

06Victims and impact

Additional victims

  • 1500+ Downstream MSP Clients

Countries affected

  • Global

07Data exposed

Data types

  • Operational Data
  • Client Credentials
  • System Files

Notable documents

  • REvil Ransom Note

08Financial damage

Estimated damage was in the hundreds of millions of dollars due to operational downtime and recovery costs.

09Timeline

  1. 2021-07-02REvil ransomware deployed via compromised Kaseya VSA product, initiating the supply chain attack.
  2. 2021-07-03Initial reports of the widespread nature of the attack and affected MSP clients.
  3. 2021-07-02Kaseya issues advisories and begins remediation efforts.

10Key figures

  • REvilThreat Actor Group · Criminal GangHighly successful, financially motivated attack

11On the record

The attack was a textbook example of a supply chain compromise, maximizing impact through a single point of failure.

Security Analysts, Describing the systemic risk posed by MSP tools.

12Reaction and fallout

Public reaction

The public reaction highlighted deep concerns regarding the security practices of the MSP industry and the systemic risk posed by third-party software. Governments and regulatory bodies increased scrutiny on critical infrastructure resilience.

Political impact

The incident spurred immediate calls for stricter cybersecurity regulations, particularly concerning supply chain risk management and the security standards of managed service tools. It accelerated the adoption of Zero Trust Architecture principles.

Geopolitical consequences

The attack underscored the global interconnectedness of critical infrastructure, making it a potential vector for state-sponsored disruption, even if the initial actor was purely criminal.

13Legal

While no specific criminal charges were publicly filed against the group, the incident led to increased civil litigation and regulatory pressure on software vendors to improve security.

Civil lawsuits

  • Class-action lawsuits against Kaseya and other vendors for inadequate security measures.

14Aftermath

Policy changes

  • Increased focus on Supply Chain Risk Management (SCRM) in corporate policy.
  • Adoption of Zero Trust Network Access (ZTNA) models across critical sectors.

Regulatory changes

  • Increased scrutiny from regulatory bodies (e.g., SEC, GDPR enforcement) regarding incident reporting and vendor risk.
  • Mandatory security audits for critical infrastructure software providers.

Security improvements

  • Mandatory network segmentation between client environments.
  • Implementation of multi-factor authentication (MFA) on all remote management tools.
  • Enhanced endpoint detection and response (EDR) solutions.

15Significance and legacy

Significance

This attack is a landmark case study in supply chain risk. It proved that compromising a single, widely used vendor product could grant access to hundreds of unrelated, critical targets simultaneously. It fundamentally changed the industry's understanding of systemic risk in the MSP sector.

Legacy

The incident accelerated the shift toward decentralized, segmented network architectures and forced major software vendors to prioritize security by design. It cemented the concept of the 'supply chain attack' as a primary threat vector in modern cybersecurity discourse.

16Disclosure and media

Authentication
Industry Threat Intelligence Reports

Media partners

  • The New York Times
  • Reuters
  • BBC News

Publishing organisations

  • Mandiant
  • CrowdStrike

17Related files

Related events

  • SolarWinds Supply Chain Attack (2020)

Inspired by

  • NotPetya (2017)

Went on to inspire

  • Colonial Pipeline Attack (2021)

18Field notes

  1. 01The attack was one of the largest and most visible examples of a supply chain compromise in the modern era.
  2. 02The sheer number of affected clients (1,500+) made it a unique case study in systemic risk.

19Resolution

The immediate threat was mitigated by network segmentation and patching, but the incident highlighted systemic vulnerabilities that required long-term policy and architectural changes across the industry.

20Sources

Official documents

  • CISA Alerts regarding Ransomware Threats
  • Kaseya Security Advisories

References

  1. [1]Mandiant Threat Intelligence Report
  2. [2]CrowdStrike Analysis of REvil
  3. [3]Industry Cybersecurity News Outlets
Fact sheetEL-0251

Dates

Event
2 Jul 2021
Started
2 Jul 2021
Ended
2 Jul 2021
Duration
1 days
Discovered
2 Jul 2021
Disclosed
2 Jul 2021
Ongoing
No

Target

Organisation
Kaseya IT Solutions
Type
Technology Company
Sector
Managed Service Provider (MSP)
Country
Global

Actor

Name
REvil
Type
Ransomware Gang
Motivation
Financial gain through ransomware deployment and extortion
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Confidential
Published
No

Money

Crypto
Bitcoin (BTC)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.