/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaseya says it obtained a universal decryptor for the REvil ransomware and is helping customers recover their data; it is unclear if Kaseya paid the ransom

Catalin Cimpanu / The Record :

The Record Catalin Cimpanu

Context & Ripple Effects

The incident spread through a compromised update for Kaseya's IT-management software, reaching managed service providers and their customers; REvil subsequently claimed responsibility and sought a $70 million bitcoin payment for a decryptor.

Kaseya now says it has the universal decryptor and is assisting recovery, shifting the immediate story from containment to access. Separate reporting says affected companies must sign NDAs before receiving the key, making Kaseya the gatekeeper for a recovery tool customers need.

First-order effects

  • Kaseya customers affected by REvil can begin restoring data through Kaseya's decryptor process rather than relying solely on their own recovery paths.
  • Kaseya takes responsibility for distributing the recovery mechanism, while the company has not said whether it paid REvil.

Second-order effects

  • Managed service providers hit through the Kaseya update must coordinate customer restoration around Kaseya's access process, including the reported NDA requirement.
  • The episode makes the recoverability of IT-management vendors' products and incident-response arrangements a more concrete concern for their customers.

Third-order effects

  • If software suppliers increasingly become the distribution point for ransomware recovery tools after supply-chain compromises, recoverability becomes a procurement criterion alongside prevention and patching.
  • Recovery access controlled by a vendor can concentrate operational leverage with that vendor during an incident, particularly where downstream managed service providers serve many customers.

The trend: Cybersecurity buying is increasingly treating recoverability—including who controls decryption and restoration—as a core dependency of software supply chains.

Discussion

  • @kaseyacorp @kaseyacorp on x
    Updates Regarding VSA Security Incident July 19, 2021 - 3:15 PM EDT Kaseya is releasing patch 9.5.7.3011 which remediates functionality issues caused by the enhanced security measures put in place and provides bug fixes (this is not a security release). https://www.kaseya.com/...
  • @nicoleperlroth Nicole Perlroth on x
    Kaseya confirms it obtained a universal decryptor and is now working with affected customers, does not say who gave it to them: https://helpdesk.kaseya.com/ ...
  • @adam_k_levin Adam Levin on x
    Kaseya has received a universal #ransomware decryptor from a “trusted third party.” https://www.bleepingcomputer.com/ ...
  • @campuscodi Catalin Cimpanu on x
    NEW: Kaseya said it obtained a REvil decryptor from “trusted third party” yesterday and has now started providing the decryptor to customers so they can recover data locked during the July 2 attack https://therecord.media/... https://twitter.com/...