Full Report
Learn how Progressive Computing fought through a mass-scale attack and came out on the other side scarred, but wiser and stronger.
Analysis Summary
# Incident Report: Kaseya VSA Supply Chain Attack (Progressive Computing)
## Executive Summary
On July 2, 2021, Progressive Computing, a Managed Service Provider (MSP), was compromised via a supply chain attack targeting Kaseya VSA software. The REvil ransomware group leveraged this access to encrypt the entire client base of Progressive Computing, affecting 2,500 endpoints. The organization successfully recovered by leaning on community support, core values, and expert legal/insurance guidance, despite lacking a formal incident response plan at the time.
## Incident Details
- **Discovery Date:** July 2, 2021
- **Incident Date:** July 2, 2021
- **Affected Organization:** Progressive Computing
- **Sector:** Managed Service Provider (MSP)
- **Geography:** United States (Operating across four time zones)
## Timeline of Events
### Initial Access
- **Date/Time:** July 2, 2021 (Friday before July 4th weekend)
- **Vector:** Supply Chain Attack
- **Details:** Attackers exploited vulnerabilities in the Kaseya VSA Remote Monitoring and Management (RMM) tool to push malicious payloads.
### Lateral Movement
- **Details:** The attack bypassed traditional perimeters by utilizing the trusted relationship and administrative permissions of the RMM tool to distribute ransomware directly to all managed endpoints.
### Data Exfiltration/Impact
- **Details:** Massive encryption event. 2,500 endpoints across 80 clients (200 physical sites) were rendered inoperable by REvil ransomware.
### Detection & Response
- **Discovery:** Rapid, simultaneous failure of client systems and ransomware notifications during a holiday weekend.
- **Response actions taken:** Immediate coordination with cyber liability insurance, engagement of specialized legal counsel, and mobilization of the entire staff to manage client communications and recovery efforts.
## Attack Methodology
- **Initial Access:** Exploitation of Kaseya VSA (Zero-day/Supply Chain).
- **Persistence:** High-level administrative access via the RMM agent.
- **Defense Evasion:** Use of trusted management software to deploy malware, often bypassing standard AV/EDR.
- **Lateral Movement:** Automated deployment from the VSA server to all connected client agents.
- **Impact:** Mass encryption using REvil ransomware.
## Impact Assessment
- **Financial:** Significant costs related to recovery, legal fees, and insurance deductibles (specific dollar amounts not disclosed).
- **Data Breach:** Critical operational data across 80 different companies was encrypted.
- **Operational:** Total business paralysis for the MSP and its 80 clients across 200 sites.
- **Reputational:** High risk, mitigated by transparent communication and a strong company culture.
## Indicators of Compromise
- **Network indicators:** Traffic associated with Kaseya VSA exploitation (specific IPs defanged: `kaseya[.]com`).
- **File indicators:** REvil ransomware binaries and encrypted file extensions.
- **Behavioral indicators:** Mass execution of administrative scripts through the RMM platform outside of normal maintenance windows.
## Response Actions
- **Containment:** Kaseya shut down its SaaS servers and advised on-premises customers to shut down VSA servers immediately.
- **Eradication:** Identification and removal of ransomware payloads from affected endpoints.
- **Recovery:** Restoration of systems, in many cases requiring manual intervention at the 200 physical client sites.
## Lessons Learned
- **Plan Deficiency:** A "half-baked" incident response plan is better than none, but a formal, tested plan is critical.
- **Terminology:** Avoid the word "Breach" initially; use "Incident" or "Event" to manage legal liabilities.
- **Culture:** A strong company culture and core values (Commitment, Team, Humble Confidence, Respect) are essential for surviving the high-stress environment of a mass-scale attack.
## Recommendations
- **Insurance:** Maintain robust cyber liability insurance and know the contact process.
- **Community:** Join MSP peer groups to share intelligence and resources during a crisis.
- **Preparedness:** Develop a formal Incident Response Plan (IRP) that accounts for supply chain compromises.
- **Tooling:** Ensure secondary security layers (like Huntress) are in place to detect anomalies that native RMM tools might miss.