financetom
Business
financetom
/
Business
/
Ransomware breach at Florida IT firm hits 200 businesses
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Ransomware breach at Florida IT firm hits 200 businesses
Jul 5, 2021 6:16 AM

Hundreds of American businesses were hit Friday by an unusually sophisticated ransomware attack that hijacked widely used technology management software from a Miami-based supplier called Kaseya.

The attackers changed a Kaseya tool called VSA, used by companies that manage technology at smaller businesses. They then encrypted the files of those providers' customers simultaneously.

Security firm Huntress said it was tracking eight managed service providers that had been used to infect some 200 clients.

Kaseya said on its own website that it was investigating a "potential attack" on VSA, which is used by IT professionals to manage servers, desktops, network devices and printers.

It said it shut down some of its infrastructure in response and that it was urging customers that used VSA on their premises to immediately turn off their servers.

"This is a colossal and devastating supply chain attack," Huntress senior security researcher John Hammond said in an email, referring to an increasingly high profile hacker technique of hijacking one piece of software to compromise hundreds or thousands of users at a time.

Hammond added that because Kaseya is plugged into everything from large enterprises to small companies "it has the potential to spread to any size or scale business." Many managed service providers use VSA, although their customers may not realize it, experts said.

Some employees at service providers said on discussion boards that their clients had been hit before they could get a warning to them.

Reuters was not able to reach a Kaseya representative for further comment. Huntress said it believed the Russia-linked REvil ransomware gang - the same group of actors blamed by the FBI for paralyzing meat packer JBS last month - was to blame for the latest ransomware outbreak.

A private security executive working on the response effort said that ransom demands accompanying the encryption ranged from a few thousand dollars to USD 5 million or more.

The corruption of an update process shows a marked escalation in sophistication from most ransomware attacks, which take advantage of security loopholes such as common passwords without two-factor authentication.

An email sent to the hackers seeking comment was not immediately returned. In a statement, the US Cybersecurity and Infrastructure Security Agency said it was "taking action to understand and address the recent supply-chain ransomware attack" against Kaseya's VSA product.

Supply chain attacks have crept to the top of the cybersecurity agenda after the United States accused hackers of operating at the Russian government's direction and tampering with a network monitoring tool built by Texas software firm SolarWinds.

Kaseya has 40,000 customers for its products, though not all use the affected tool.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Don't Judge A Candy By Its Cover - Hershey Reportedly Defends Lawsuit Against Reese's Candies
Don't Judge A Candy By Its Cover - Hershey Reportedly Defends Lawsuit Against Reese's Candies
Sep 9, 2024
The Hershey Company ( HSY ) shares are trading slightly higher premarket Monday. Hershey has reportedly asked a U.S. judge to dismiss a lawsuit alleging it misled consumers about Reese’s peanut butter candies. In its request, Hershey criticized the class action litigation as baseless, targeting issues related to product packaging, reported Reuters. The report noted that the consumers suing Hershey...
ZIM Integrated Shipping Services Partners With Mediterranean Shipping on US-Asia Routes
ZIM Integrated Shipping Services Partners With Mediterranean Shipping on US-Asia Routes
Sep 9, 2024
08:49 AM EDT, 09/09/2024 (MT Newswires) -- ZIM Integrated Shipping Services ( ZIM ) said Monday it has entered a three-year agreement with Mediterranean Shipping on routes between Asia and the US East Coast and Gulf of Mexico. The new services are scheduled to be launched in February, subject to regulatory approvals and filings. The expanded network will allow ZIM...
Scotiabank Previews Bank of Canada's Governor Speech on Tuesday
Scotiabank Previews Bank of Canada's Governor Speech on Tuesday
Sep 9, 2024
09:06 AM EDT, 09/09/2024 (MT Newswires) -- Bank of Canada Governor Tiff Macklem will speak on Tuesday in London at 8:25 a.m. ET before the Canada-United Kingdom Chamber of Commerce, noted Scotiabank. The governor's topic will be Global trade from a Canadian perspective. His speech will land at 8:10 a.m. ET on the bank's website and there will be a...
Donegal Group Insider Sold Shares Worth $457,080, According to a Recent SEC Filing
Donegal Group Insider Sold Shares Worth $457,080, According to a Recent SEC Filing
Sep 9, 2024
09:06 AM EDT, 09/09/2024 (MT Newswires) -- Vincent Anthony Viozzi, Sr. VP & Chief Inv Officer, on September 06, 2024, sold 30,000 shares in Donegal Group ( DGICA ) for $457,080. Following the Form 4 filing with the SEC, Viozzi has control over a total of 13,073 shares of the company, with 9,891 shares held directly and 3,182 shares controlled...
Copyright 2023-2025 - www.financetom.com All Rights Reserved