Site navigation

Kaseya Receives Decryptor After Ransomware Attack

Michael Behr

,

Kaseya decryptor
While the company can now decipher encrypted data, questions remain about the source of the decryptor.

Kaseya has said it has obtained a decryptor to restore data that was encrypted as part of a sweeping ransomware attack.

In a year of major ransomware attacks and data breaches, the Kaseya attack ranks as one the biggest. The attack saw hackers from the REvil group compromise the IT management software provider, whose products are used by hundreds of third parties.

As such, the ransomware spread across an estimated 1,500 systems belonging to 60 of Kaseya’s customers, encrypting massive amounts of data.

“We obtained the decryptor yesterday from a trusted third party and have been using it successfully on affected customers,” reads an emailed statement from Kaseya Senior VP of Corporate Marketing Dana Liedholm.

“We are providing tech support to use the decryptor. We have a team reaching out to our customers, and I don’t have more detail right now.”

While REvil previously demanded $70 million in Bitcoin for a decryptor, it is unknown if Kaseya paid the ransom. As such, it is uncertain where the decryptor came from – law enforcement and private cybersecurity groups offer their own decryptors. Conceivably, ransomware groups have been known to provide the means for companies to decrypt their data for free

However, with their payment site down, many of the attacks smaller victims would have been unable to buy the decryptor if they needed it.

REvil was also behind the JBS ransomware attack, which saw one of the world’s largest meat suppliers pay the hackers around $11 million.


Recommended


By their very nature, it is difficult to know exactly what cybercrime groups are up to. A few weeks ago, REvil itself disappeared from the dark web, its name-and-shame blog and payments website becoming inaccessible.

This has prompted speculation about what happened to the group. The move coincided with a phone call between US President Biden, who has vowed to get tough on cybercrime, and Russian President Putin, where REvil is widely believed to be based.

As such, one theory is that authorities, either in Russia or America were able to take down REvil’s infrastructure, or that the group is going to ground due to their high-profile attacks putting them under additional scrutiny, or even that they were struck by technical problems.

It is true that some hacker groups have had a conscience in the past. A minor hacker group using the Ziggy ransomware offered refunds to their victims. The people behind a ransomware attack on a German hospital last year, which saw a woman die as an indirect result, worked to break their own encryption.

However, in each of these cases, the main motivation is most likely training to avoid attracting attention from authorities.

Michael Behr

Senior Staff Writer

Latest News

Cybersecurity Editor's Picks

OpenAI Flags Potential ‘Critical’ Cyber Risk From Astra

Business Featured Funding

VC Access Expanded For Early-stage Companies in UK

Business Editor's Picks Technology

Comment | Managing Risk in Multi-Supplier SaaS Procurements

AI Recruitment Skills

Young Scots Seek Jobs That AI Can’t Replace