In a post on the REvil dark web blog, the gang takes credit for the Kaseya attack, claims it infected 1M+ systems, and demands $70M in bitcoin for the decryptor
and Kaseya's $70M REvil demand Usama Jawad / Neowin : Ransomware group demands $70 million in Bitcoin for “universal decryptor” Gavin Phillips / MUO : Ransomware Group Demands $70m Bitcoin Payment to Unlock Infected Computers Jason England / Laptop Mag : REvil ransomware hackers demand $70 million — businesses worldwide go down Abhimanyu Ghoshal / TNW : REvil's humungous $70M Kaseya ransomware attack, explained Yadullah Abidi / Candid.Technology : REvil's Kaseya attack might be the largest ransomware attack in history Davey Winder / Forbes : $70 Million Demanded As REvil Ransomware Attackers Claim 1 Million Systems Hit Tweets: Will Dormann / @wdormann : Kaseya: Please disable antivirus protection for these directories to allow the Kaseya Agent to “function appropriately” https://helpdesk.kaseya.com/ ... https://twitter.com/... Catalin Cimpanu / @campuscodi : Some questions in regards to the Kaseya incident: -How did REvil learn of the VSA exploit? -Did they have access to Kaseya's vulnerability disclosure systems? -Where they provided the exploit by a 3rd-party? -Was that 3rd-party an RU intelligence agency or exploit broker? Dustin Volz / @dnvolz : Kaseya CEO's says the hackers behind the far-reaching ransomware attack are demanding a $70 million payment. https://www.wsj.com/... @kdka : Russia-linked group REvil infected thousands of victims in at least 17 countries via software company Kaseya, experts say. https://www.cbsnews.com/... Raphael Satter / @razhael : Kaseya CEO Fred Voccola on whether he's going to pay the $70 million ransom or negotiate with REvil: ""I can't comment ‘yes,’ ‘no,’ or ‘maybe’ [...] No comment on anything to do with negotiating with terrorists in any way." https://www.reuters.com/... Raphael Satter / @razhael : Some highlights from our interview with the @KaseyaCorp CEO: * Hasn't seen evidence the hackers were tipped off to the vulnerability * Doesn't believe they were in his company's network * Says between 800 & 1500 business affected overall https://www.reuters.com/... @wsj : The chief executive of Kaseya, the company whose software was targeted, told the White House that it wasn't aware of any critical infrastructure that had been hit by the ransomware https://www.wsj.com/... Catalin Cimpanu / @campuscodi : Kaspersky stats about the Kaseya attack are very different from the ESET ones https://twitter.com/... Kevin Beaumont / @gossithedog : Put it this way, the Kaseya VSA vuln is in a .asp script - not even ASPX. The code dates back 15 or so years. Enterprise IT is held together by string, and ransomware gangs are the match. 🔥 https://twitter.com/... @pwnallthethings : So if you want a spicy take, although the direct impact of this is relatively small /so far/, its strategic impact dwarfs everything else in cybersecurity this year by a margin including Exchange hack, Colonial pipeline hack, and maybe even SolarWinds. https://twitter.com/... Catalin Cimpanu / @campuscodi : Why would REvil pull such a brash attack right after the Colonial and JBS attacks and the political mess/fallouts from those incidents? -Wouldn't this attack confirm that REvil had some sort of approval from a RU agency before doing something this destructive? Catalin Cimpanu / @campuscodi : Was the timing of the attack on the July 4 weekend a decision made for political reasons or was it REvil's typical modus operandi to hit over big western holiday breaks (which they have done many times before)? -Why are they asking a payment for an universal decrypter? Catalin Cimpanu / @campuscodi : Did they realize that negotiating ransoms with thousands of companies at the same time is not worth the effort? -Will that universal decrytper even work, or are companies going to encounter bugs with large files? -Will Kaseya even consider paying? Nicholas Weaver / @ncweaver : This is possibly even MORE disturbing than a supply chain attack, because it brings up the possibility at least of a “lab leak”, the ransomware gang learning of the exploit itself OR at least plans to patch it. Leaks like this don't affect a single vendor. https://twitter.com/... Catalin Cimpanu / @campuscodi : Scoop/breaking: The REvil ransomware gang is asking for $70 million to publish a universal decryptor that can unlock all computers locked during the Kaseya incident https://therecord.media/... https://twitter.com/... Brad Sams / @bdsams : The legitimacy of BTC would be vastly improved if it wasn't universally associated with ransom payments. https://twitter.com/... Catalin Cimpanu / @campuscodi : Apparently, this would be one gigantic discount. So nice of REvil... 😅 https://twitter.com/... Catalin Cimpanu / @campuscodi : In a message posted on their dark web blog, the REvil gang officially took credit for the attack for the first time and claimed they locked more than one million systems during the Kaseya incident.
Context & Ripple Effects
The attack was previously traced to a malicious update for Kaseya’s IT-management software, reaching managed service providers and their customers rather than a single enterprise. REvil’s public demand turns that distribution mechanism into a single negotiation over a universal decryptor.
The claimed scale exceeds Kaseya CEO Fred Voccola’s estimate of 800–1,500 affected businesses, while security firms reported differing scope estimates. That gap makes the attackers’ one-million-system claim unverified, but does not change the broad exposure created by the MSP channel.
First-order effects
- Kaseya, affected managed service providers, and their customers must weigh recovery options against REvil’s $70 million Bitcoin demand for a universal decryptor.
- REvil gains leverage by offering one decryptor for infections propagated through Kaseya’s software, rather than negotiating separately with each affected organization.
Second-order effects
- Managed service providers face immediate pressure from customers to demonstrate how they isolate, patch, and restore systems when a shared management platform becomes the attack path.
- Kaseya’s recovery response becomes the critical operational dependency; related coverage later reports Kaseya obtaining a universal decryptor to help customers restore data.
Third-order effects
- Software vendors that sit at the center of customer administration carry concentrated security and recovery risk: one compromised update can create a multi-company incident and centralize extortion leverage.
- If buyers treat recoverability as a vendor-selection requirement, MSP and IT-management providers will compete more on restoration capabilities and supply-chain controls, not only on operational reach.
The trend: Ransomware groups are targeting software distribution and managed-service chokepoints to convert one compromise into leverage over many downstream organizations.