THREAT BRIEFING · 26.07.2026 DEENFRES

Case Studies

The Kaseya Attack: Lessons from the Largest Ransomware Incident of 2021

By Tobias Massow · September 10, 2021 · 5 min read

The ransomware attack on Kaseya in July 2021 impacted over 1,500 companies worldwide – through a single software vulnerability. The incident reveals how vulnerable global supply chains are and why supply chain security must become a top executive priority.

TL;DR

Anatomy of the Attack

On 2 July 2021 – timed precisely for the US Independence Day holiday weekend – the REvil group launched its assault. Attackers exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and management (RMM) platform widely used by managed service providers (MSPs). Once MSP systems were compromised, ransomware was automatically deployed across their clients’ networks.

The timing was no coincidence: holiday periods mean reduced IT staffing and slower response times. Within hours, organizations across 17 countries were affected – including Swedish supermarket chain Coop, which was forced to close 800 stores.

Why Supply-Chain Attacks Are So Effective

The Kaseya incident illustrates the multiplier effect inherent in supply-chain attacks. Rather than targeting thousands of organizations individually, attackers need only one entry point in the supply chain. The trusted relationship between software vendor and customer becomes a weapon: software updates and remote access are rarely questioned because they’re part of normal operations.

Following the SolarWinds breach at the end of 2020, Kaseya marked the second major supply-chain attack within just months. This pattern will continue – attackers have realized that leveraging suppliers delivers far greater leverage than direct assaults.

Lessons for Enterprises

Organizations must systematically assess their dependencies on third-party vendors. Minimum requirements include a Software Bill of Materials (SBOM) for all deployed tools, zero-trust principles – even for trusted vendors – network segmentation to limit blast radius, and tested incident-response plans with clearly defined escalation paths. The Kaseya case also underscores a critical truth: offline backups remain the final lifeline.

Key Facts at a Glance

Attack date: 2 July 2021 (US holiday weekend)

Attacker: REvil (a Russian ransomware group)

Affected: 1,500+ organizations across 17 countries

Ransom demand: $70 million (the highest ever demanded)

Attack vector: Zero-day in Kaseya VSA (CVE-2021-30116)

Sources: CISA Advisory, Kaseya Incident Report, July 2021

Fact: According to Cybereason, 77% of ransomware victims who paid the ransom were attacked again.

Fact: Per the Allianz Risk Barometer 2025, cyberattacks rank as the top global business risk.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What exactly is a supply-chain attack?

In a supply-chain attack, adversaries do not target the ultimate victim directly. Instead, they compromise a supplier or software vendor within the victim’s supply chain. Malware then spreads to all downstream customers via trusted channels – such as software updates. In the Kaseya case, over 1,500 organizations were affected through a single entry point.

Why do hackers launch attacks on holidays?

Holidays and weekends typically mean reduced IT staffing, less frequent monitoring, and longer response times. REvil deliberately chose the US Independence Day weekend. The FBI and CISA regularly warn of heightened attack risks during such periods.

How can organizations defend against supply-chain attacks?

Complete protection is difficult – but risk can be significantly reduced through network segmentation, zero-trust architecture (even for trusted vendors), regular security audits of suppliers, Software Bill of Materials (SBOM), and offline backups as the last line of defense.

What happened to REvil?

The REvil group briefly disappeared from view in July 2021, re-emerged in September, and was ultimately dismantled in January 2022 by Russia’s FSB – under pressure from the United States. Several members were arrested. However, its infrastructure was subsequently taken over by successor groups.

What is a Software Bill of Materials (SBOM)?

An SBOM is a complete, machine-readable inventory of all software components, libraries, and dependencies within a product. It enables organizations to rapidly determine whether they’re affected when a vulnerability is disclosed. Following the Kaseya incident and the Log4j crisis, regulators increasingly mandate SBOMs.

Further Reading Across the Network

Supply-chain risks in the cloud era, on cloudmagazin: cloudmagazin.com

IT security strategies for SMEs, on mybusinessfuture: mybusinessfuture.com

How CIOs manage supply-chain risk, on Digital Chiefs: digital-chiefs.de

Related Articles

Header Image Source: Pexels / Brett Sayles

Further reading

Case Studies · July 5, 2026

Südwestfalen IT: The Lesson of Municipal IT

Two years after the Southwestphalia IT attack, Security Today dissects: VPN without MFA, rebuilding without ransom, and five lessons for municipal IT.

A magazine by Evernine Media GmbH