Kaseya says it obtained a universal decryptor for the REvil ransomware and is helping customers recover their data; it is unclear if Kaseya paid the ransom
Catalin Cimpanu / The Record :
Context & Ripple Effects
The incident spread through a compromised update for Kaseya's IT-management software, reaching managed service providers and their customers; REvil subsequently claimed responsibility and sought a $70 million bitcoin payment for a decryptor.
Kaseya now says it has the universal decryptor and is assisting recovery, shifting the immediate story from containment to access. Separate reporting says affected companies must sign NDAs before receiving the key, making Kaseya the gatekeeper for a recovery tool customers need.
First-order effects
- Kaseya customers affected by REvil can begin restoring data through Kaseya's decryptor process rather than relying solely on their own recovery paths.
- Kaseya takes responsibility for distributing the recovery mechanism, while the company has not said whether it paid REvil.
Second-order effects
- Managed service providers hit through the Kaseya update must coordinate customer restoration around Kaseya's access process, including the reported NDA requirement.
- The episode makes the recoverability of IT-management vendors' products and incident-response arrangements a more concrete concern for their customers.
Third-order effects
- If software suppliers increasingly become the distribution point for ransomware recovery tools after supply-chain compromises, recoverability becomes a procurement criterion alongside prevention and patching.
- Recovery access controlled by a vendor can concentrate operational leverage with that vendor during an incident, particularly where downstream managed service providers serve many customers.
The trend: Cybersecurity buying is increasingly treating recoverability—including who controls decryption and restoration—as a core dependency of software supply chains.