Security researchers at Huntress investigate why the July 2021 Kaseya VSA ransomware attack by REvil only affected 50-60 MSPs out of a potential 17,000+ customers. The post analyzes the three-step attack chain (authentication bypass via Agent GUID, arbitrary file upload, remote code execution) and explores five hypotheses for how attackers obtained valid Agent GUIDs without brute-forcing: predicting GUIDs, registering a rogue agent, compromising a VSA-managed host, exploiting known vulnerabilities like CVE-2021-30116 or CVE-2021-30117, or using previously leaked Agent GUIDs from dark web dumps. No definitive answer is reached, but the analysis highlights that the blast radius was far smaller than it could have been and urges the industry to understand why.