Kaseya has said it has obtained a decryptor to restore data that was encrypted as part of a sweeping ransomware attack.
In a year of major ransomware attacks and data breaches, the Kaseya attack ranks as one the biggest. The attack saw hackers from the REvil group compromise the IT management software provider, whose products are used by hundreds of third parties.
As such, the ransomware spread across an estimated 1,500 systems belonging to 60 of Kaseya’s customers, encrypting massive amounts of data.
“We obtained the decryptor yesterday from a trusted third party and have been using it successfully on affected customers,” reads an emailed statement from Kaseya Senior VP of Corporate Marketing Dana Liedholm.
“We are providing tech support to use the decryptor. We have a team reaching out to our customers, and I don’t have more detail right now.”
While REvil previously demanded $70 million in Bitcoin for a decryptor, it is unknown if Kaseya paid the ransom. As such, it is uncertain where the decryptor came from – law enforcement and private cybersecurity groups offer their own decryptors. Conceivably, ransomware groups have been known to provide the means for companies to decrypt their data for free
However, with their payment site down, many of the attacks smaller victims would have been unable to buy the decryptor if they needed it.
REvil was also behind the JBS ransomware attack, which saw one of the world’s largest meat suppliers pay the hackers around $11 million.
Recommended
- Founders explain inspiration behind “Respect in Security” initiative
- Remote symptom monitoring boosts cancer patient quality of life
- Public access to electric vehicle charge points a “postcode lottery”
By their very nature, it is difficult to know exactly what cybercrime groups are up to. A few weeks ago, REvil itself disappeared from the dark web, its name-and-shame blog and payments website becoming inaccessible.
This has prompted speculation about what happened to the group. The move coincided with a phone call between US President Biden, who has vowed to get tough on cybercrime, and Russian President Putin, where REvil is widely believed to be based.
As such, one theory is that authorities, either in Russia or America were able to take down REvil’s infrastructure, or that the group is going to ground due to their high-profile attacks putting them under additional scrutiny, or even that they were struck by technical problems.
It is true that some hacker groups have had a conscience in the past. A minor hacker group using the Ziggy ransomware offered refunds to their victims. The people behind a ransomware attack on a German hospital last year, which saw a woman die as an indirect result, worked to break their own encryption.
However, in each of these cases, the main motivation is most likely training to avoid attracting attention from authorities.





