/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

President Biden says he has directed US intelligence agencies to investigate the Kaseya ransomware attack and adds “we're not certain” who is behind the attack

Trevor Hunnicutt / Reuters :

Reuters Trevor Hunnicutt

Context & Ripple Effects

The Kaseya inquiry arrived amid a widening U.S. ransomware response: the FBI had already said it was investigating roughly 100 ransomware variants, many with links to Russia. The administration had also attributed the SolarWinds operation to Russia while saying it was executed from within the U.S.

The immediate uncertainty over attribution matters because a later Biden warning to Putin over ransomware turns the incident from a technical breach into a bilateral security issue. Related reporting also indicates Kaseya had been alerted in April to a flaw later exploited in the attack.

First-order effects

  • U.S. intelligence agencies are tasked with establishing responsibility for the Kaseya attack, while Biden publicly avoids assigning blame before that assessment is complete.
  • Kaseya faces sharper scrutiny of its vulnerability-reporting and remediation process after the reported prior warning about an exploited flaw.

Second-order effects

  • The attribution process gives the Biden administration the evidentiary basis for its subsequent warning to Putin, tying ransomware response more directly to U.S.-Russia relations.
  • Security researchers’ disclosure practices become more consequential for software vendors as prior reports of flaws can become central to post-incident accountability.

Third-order effects

  • Repeated ransomware incidents are pushing U.S. cyber policy toward treating major attacks as a national-security and diplomatic problem, not solely an FBI-led criminal investigation.
  • If this pattern persists, vendors’ handling of reported vulnerabilities will be judged alongside attacker attribution in the public response to major breaches.

The trend: Ransomware is being elevated from an enterprise-security risk to a test of coordinated U.S. intelligence, law-enforcement, and diplomatic response.

Discussion

  • @serghei @serghei on x
    “Although the scale of this incident may make it so that we are unable to respond to each victim individually, all information we receive will be useful in countering this threat.” 👀 https://twitter.com/...
  • @0xdude Victor Gevers on x
    During the last 48 hours, the number of Kaseya VSA instances that are reachable from the internet has dropped from over 2.200 to less than 140 in our last scan today. https://csirt.divd.nl/...
  • @esetresearch @esetresearch on x
    #ESETresearch responded to ransomware deployed as supply-chain attack against #Kaseya VSA users attributed to #REvil beginning Friday afternoon EDT (US)/evening CEST (Europe). Detection was added for Win32/Filecoder.Sodinokibi.N on Friday shortly after.https://www.welivesecurity.…
  • @uscert_gov Us-Cert on x
    .@CISAgov and @FBI strongly recommend MSPs and #MSP customers affected by the Kaseya VSA supply-chain #ransomware attack take immediate action. See https://us-cert.cisa.gov/... for recommendations. #Cybersecurity #InfoSec #Ransomware
  • @kaseyacorp @kaseyacorp on x
    Updates Regarding VSA Security Incident July 4, 2021 - 10:00 AM EDT Next Update will be published July 4, 2021, in the early afternoon EDT https://www.kaseya.com/...
  • @_johnhammond John Hammond on x
    If you haven't seen it, Kaseya has now shared their own detection tool. From their report, “The new Compromise Detection Tool was rolled out last night to almost 900 customers who requested the tool.” https://helpdesk.kaseya.com/ ...
  • @raj_samani Raj Samani on x
    Some small respite for victims of the Kaseya attack - “REvil representatives have told victims that they only encrypted networks, and nothing more. This means that REvil likely did not steal any of the victims' data” https://www.bleepingcomputer.com/ ... #ransomware #malware #cyb…
  • @bad_packets Bad Packets Llc on x
    @FBI The vendor says, “Only a very small percentage of our customers were affected - currently estimated at fewer than 40 worldwide.” The FBI says, “Although the scale of this incident may make it so that we are unable to respond to each victim individually.” 🤔
  • @fbi @fbi on x
    #FBI Statement on Kaseya Ransomware Attack @CISAgov https://www.fbi.gov/... https://twitter.com/...
  • @randahabib Randa Habib on x
    President Joe Biden said he has directed U.S. intelligence agencies to investigate who was behind a sophisticated ransomware attack that hit hundreds of American businesses and led to suspicions of Russian gang involvement. https://www.reuters.com/...