/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaseya says it obtained a universal decryptor for the REvil ransomware and is helping customers recover their data; it is unclear if Kaseya paid the ransom

Remote management software vendor Kaseya said today it obtained a universal decryptor for the REvil ransomware and is now in the process …

The Record Catalin Cimpanu

Context & Ripple Effects

The incident began with a malicious update to Kaseya's management software that reached hundreds of managed service providers and their customers. REvil subsequently claimed responsibility and sought $70 million for a decryptor, as reported in its public ransom demand.

Recovery has now shifted from containment to access: Kaseya is distributing the decryptor while affected companies reportedly must sign NDAs before receiving it. Whether Kaseya paid REvil remains unresolved in the supplied coverage.

First-order effects

  • Kaseya can begin restoring affected customers' data with a single decryptor rather than leaving each victim to pursue a separate recovery path.
  • Affected companies' access to the decryption key is mediated by Kaseya, with the related coverage reporting NDA requirements before the key is provided.

Second-order effects

  • Managed service providers hit through the Kaseya update must coordinate customer restoration around Kaseya's decryption process, concentrating recovery operations at the software vendor.
  • The NDA condition limits how freely affected companies can share details of the key-access and recovery process with peers and customers.

Third-order effects

  • The episode makes recoverability a more central procurement test for remote-management software: buyers inherit not only a vendor's update channel but also its ability to coordinate restoration after a compromise.
  • If attacks continue to propagate through management platforms, resilience will increasingly be judged at the provider-and-service-provider level rather than by an individual customer's defenses alone.

The trend: Ransomware risk is moving from individual endpoints to software-management supply chains, making coordinated recovery capability part of the product buyers evaluate.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    Kaseya confirms it obtained a universal decryptor and is now working with affected customers, does not say who gave it to them: https://helpdesk.kaseya.com/ ...
  • @adam_k_levin Adam Levin on x
    Kaseya has received a universal #ransomware decryptor from a “trusted third party.” https://www.bleepingcomputer.com/ ...
  • @campuscodi Catalin Cimpanu on x
    NEW: Kaseya said it obtained a REvil decryptor from “trusted third party” yesterday and has now started providing the decryptor to customers so they can recover data locked during the July 2 attack https://therecord.media/... https://twitter.com/...