Five former Kaseya employees say they have warned the company about its lax security practices, and were laid off or quit as Kaseya failed to address the issues
- Ransomware attack hit as many as 1,500 businesses this month — Workers say Kaseya ignored warnings about key vulnerabilities
Bloomberg
Context & Ripple Effects
The attack had already been linked to an exploited flaw that a Dutch researcher group said it reported to Kaseya in April, while Kaseya’s CEO put the impact at 800 to 1,500 affected businesses. The former employees’ accounts add an alleged internal-warning track to that external disclosure timeline.
That shifts attention from the exploit alone to Kaseya’s security governance: whether warnings from researchers and staff were identified, escalated, and acted on before customers were exposed.
First-order effects
Kaseya faces more pointed scrutiny over its handling of security reports, because the employees’ allegations parallel the previously reported external warning about an exploited flaw.
Businesses affected by the ransomware incident now have allegations of ignored internal warnings alongside the reported scale of the attack, sharpening the accountability questions directed at Kaseya.
Security researchers and enterprise customers gain a clearer basis to evaluate Kaseya not only on vulnerability remediation, but on how it receives and escalates reports from outside and inside the company.
Third-order effects
If reports of missed internal and external warnings recur across security vendors, breach response will be judged increasingly as a governance and disclosure process rather than solely as a technical failure.
The Kaseya episode points toward greater pressure for security suppliers to demonstrate auditable channels for vulnerability reporting and escalation before an incident spreads through customers.
The trend: Ransomware incidents are expanding the accountability standard for security vendors from patching vulnerabilities to proving that warnings were surfaced and acted on.
Executives at Miami-based Kaseya were warned of critical security flaws in its software before a ransomware attack that affected as many as 1,500 companies, according to five ex-employees https://www.bloomberg.com/...
#Truesec founder @MarcusSwede about the #Kaseya breach on BNN Bloomberg: “We found severe and exploitable vulnerabilities in only a few hours of research” https://www.bnnbloomberg.ca/ ...
If an organization's approach to cyber security is maybe patch and pray, it will pay - as will its clients. Is that the case here? You decide. https://www.bloomberg.com/...
According to two employees, “executives were told that Kaseya's Virtual System Administrator software, known as VSA was so antiquated and riddled with problems that it should be replaced. That was the vehicle REvil used to stage its attack.” https://www.bloomberg.com/...
“One of the former employees said that in early 2019 he sent company leaders a 40-page memo detailing security concerns and was fired about two weeks later, which he believed was related to his repeated efforts to flag the problems.” Don't let private equity own software firms. h…
New: Former employees at US tech firm Kaseya told us they tried to raise alarm repeatedly about internal security failings before the recent hack of the company's software that led to one of the worst ever ransomware incidents https://www.bloomberg.com/...