logo

Lessons Learned During the Kaseya VSA Supply Chain Attack | Huntress

ID: ec5f233e-1e08-5205-8a14-a3c5efc322f0

STIX ID: report--ec5f233e-1e08-5205-8a14-a3c5efc322f0

Feed Name: Huntress Blog

Threat Score
90/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

On July 2, 2021 the REvil ransomware group carried out a sophisticated supply-chain attack against Kaseya VSA that leveraged an authentication bypass, arbitrary file upload, and remote code execution to compromise 50–60 MSPs and approximately 1,500–2,000 customer endpoints; the report details the attack chain and payloads (agent.crt and Screenshot.jpg), Huntress’s rapid-response actions (including a vaccine), the later appearance of a universal decryption key, and recommended lessons for vendor security, configuration, and incident response preparedness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.