A detailed post-mortem of the July 2021 REvil ransomware supply chain attack on Kaseya VSA, which compromised 50–60 MSPs and up to 2,000 downstream customers. The attack exploited an authentication bypass, arbitrary file upload, and code execution to deploy ransomware across all connected endpoints simultaneously. Huntress describes its own rapid response, including developing and deploying a vaccine within hours. Key lessons include regularly evaluating your security stack, properly configuring vendor tools, and maintaining a tested incident response plan, since cyberattacks are treated as inevitable rather than preventable.

8m read timeFrom huntress.com
Post cover image
Table of contents
What HappenedLessons Learned
2 Impressions