/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Experts working with companies affected by the Kaseya ransomware attack say Kaseya is requiring companies to sign NDAs before providing access to decryption key

Washington (CNN)On Thursday, the software company Kaseya announced that it could help unlock any of its customers' systems …

CNN

Context & Ripple Effects

The attack spread through Kaseya’s IT-management software to managed service providers and their customers, while Kaseya’s CEO later put the impact at 800 to 1,500 affected businesses. Kaseya has since said it obtained a universal REvil decryptor to help customers recover data.

The NDA requirement turns access to that recovery tool into a controlled process. It matters because the same event had already raised questions about a flaw reportedly disclosed to Kaseya before the attack.

First-order effects

  • Affected companies must sign Kaseya’s NDA before receiving the decryption key, making Kaseya the gatekeeper for both recovery access and communications around it.
  • Kaseya can distribute the universal decryptor to customers while constraining what recipients publicly disclose about the recovery process.

Second-order effects

  • Managed service providers and their downstream customers face a more centralized recovery channel after an attack that had already propagated through provider relationships.
  • The NDA condition may limit shared operational detail from affected organizations just as the prior disclosure of an exploited flaw has intensified attention on Kaseya’s response.

Third-order effects

  • The episode points to software-management vendors becoming crisis-control hubs when a compromised update reaches many businesses through managed service providers.
  • If recovery tools are routinely distributed under confidentiality terms, ransomware incident transparency may depend increasingly on vendors rather than on the affected customer base.

The trend: Ransomware attacks on IT-management software are concentrating both operational disruption and recovery control in the vendor at the center of the software supply chain.

Discussion

  • @b_fung Brian Fung on x
    Kaseya, for its part, said “fewer than 24 hours” elapsed between when it obtained the decryptor and when it announced its existence. The key is still a measure of hope for a range of affected companies stranded by REvil's disappearance: https://www.cnn.com/...
  • @b_fung Brian Fung on x
    Customers of Kaseya who spent 2,000+ hours recovering from REvil ransomware are frustrated the company only yesterday (and to everyone's surprise) said it'd obtained a decryption key that could unlock their systems. With @NatashaBertrand and @MarquardtA: https://www.cnn.com/...
  • @b_fung Brian Fung on x
    The release of a decryption key also raises fresh questions about Kaseya's response to the hack. Did it pay a ransom to get the key? If so, how did it communicate with REvil? The company won't say, and is requiring companies to sign NDAs to get the key. https://www.cnn.com/...
  • @kaseyacorp @kaseyacorp on x
    Updates Regarding VSA Security Incident July 19, 2021 - 3:15 PM EDT Kaseya is releasing patch 9.5.7.3011 which remediates functionality issues caused by the enhanced security measures put in place and provides bug fixes (this is not a security release). https://www.kaseya.com/...
  • @nicoleperlroth Nicole Perlroth on x
    Kaseya confirms it obtained a universal decryptor and is now working with affected customers, does not say who gave it to them: https://helpdesk.kaseya.com/ ...
  • @adam_k_levin Adam Levin on x
    Kaseya has received a universal #ransomware decryptor from a “trusted third party.” https://www.bleepingcomputer.com/ ...
  • @campuscodi Catalin Cimpanu on x
    NEW: Kaseya said it obtained a REvil decryptor from “trusted third party” yesterday and has now started providing the decryptor to customers so they can recover data locked during the July 2 attack https://therecord.media/... https://twitter.com/...