logo

Customer Advisory Kaseya VSA Ransomware Incident

ID: fccb50b5-11ef-59f1-981f-90b649af9de5

STIX ID: report--fccb50b5-11ef-59f1-981f-90b649af9de5

Feed Name: Mitiga

Threat Score
90/100

Date Published: 2026-07-22

Date Updated: 2026-07-29

...
...

#### Executive Summary: This report documents a large-scale supply-chain ransomware attack (REvil/Sodinokibi) against Kaseya VSA on July 2, 2021, where attackers exploited a code-injection vulnerability to distribute a malicious update (agent.crt → agent.exe) via MSP-hosted VSA servers, encrypting endpoints across numerous organizations worldwide; the report includes impacted groups, a timeline, IOCs (files, hashes, registry keys, attacker IPs, log artefacts), and concrete mitigation and incident-response recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.