Kaseya gets master decryption key after July 4 global attack

Advertisement

Advertise with us

BOSTON (AP) — The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 22/07/2021 (1843 days ago), so information in it may no longer be current.

BOSTON (AP) — The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident.

Kaseya spokeswoman Dana Liedholm would not say Thursday how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims. The cybersecurity firm Emsisoft confirmed that the key worked and was providing support.

Ransomware analysts offered multiple possible explanations for why the master key, which can unlock the scrambled data of all the attack’s victims, has now appeared. They include: Kaseya paid; a government paid; a number of victims pooled funds; the Kremlin seized the key from the criminals and handed it over through intermediaries — or perhaps the main attacker didn’t get paid by the gang whose ransomware was used.

A sign that reads:
A sign that reads: "Coop Forum supermarket in Vastberga is closed due to IT disturbances, no prognosis as to when we will open again", on a closed Coop supermarket store in the suburb of Vastberga, Stockholm, Sweden, Saturday July 3, 2021. Cybersecurity teams worked feverishly Sunday July 4, 2021, to stem the impact of the single biggest global ransomware attack on record, with some details emerging about how the Russia-linked gang responsible breached the company whose software was the conduit. The Swedish grocery chain Coop said most of its 800 stores would be closed for a second day Sunday because their cash register software supplier was crippled. (Jonas Ekstromer/TT via AP, File)

The Russia-linked criminal syndicate that supplied the malware, REvil, disappeared from the internet on July 13. That likely deprived whoever carried out the attack of income because such affiliates split ransoms with the syndicates that lease them the ransomware. In the Kaseya attack, the syndicate was believed overwhelmed by more ransom negotiations than it could manage, and decided to ask $50 million to $70 million for a master key that would unlock all infections.

By now, many victims will have rebuilt their networks or restored them from backups.

It’s a mixed bag, Liedholm said, because some “have been in complete lockdown.” She had no estimate of the cost of the damage and would not comment on whether any lawsuits may have been filed against Kaseya. It is not clear how many victims may have paid ransoms before REvil went dark.

The so-called supply-chain attack of Kaseya was the worst ransomware attack to date because it spread through software that companies known as managed service providers use to administer multiple customer networks, delivering software updates and security patches.

President Joe Biden called his Russian counterpart, Vladimir Putin, afterward to press him to stop providing safe haven for cybercriminals whose costly attacks the U.S. government deems a national security threat. He has threatened to make Russia pay a price for failing to crack down, but has not specified what measures the U.S. may take.

FILE - In this July 3, 2021 file photo, a sign reads:
FILE - In this July 3, 2021 file photo, a sign reads: " Temporarily Closed. We have an IT-disturbance and our systems are not functioning", posted in the window of a closed Coop supermarket store in Stockholm, Sweden. Cybersecurity teams worked feverishly Sunday July 4, 2021, to stem the impact of the single biggest global ransomware attack on record, with some details emerging about how the Russia-linked gang responsible breached the company whose software was the conduit. The Swedish grocery chain Coop said most of its 800 stores would be closed for a second day Sunday because their cash register software supplier was crippled. (Ali Lorestani/TT via AP, File)

If the universal decryptor for the Kaseya attack was turned over without payment, it would not be the first time ransomware criminals have done that. It happened after the Conti gang hobbled Ireland’s national health care service in May and the Russian Embassy in Dublin offered “to help with the investigation.”

FILE - In this July 3, 2021, file photo, a closed Coop supermarket store in the suburb of Vastberga, Stockholm. The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident. Kaseya spokeswoman Dana Liedholm would not say Thursday, July 22, how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims. (Jonas Ekstromer/TT via AP, File)
FILE - In this July 3, 2021, file photo, a closed Coop supermarket store in the suburb of Vastberga, Stockholm. The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident. Kaseya spokeswoman Dana Liedholm would not say Thursday, July 22, how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims. (Jonas Ekstromer/TT via AP, File)
FILE - In this July 3, 2021 file photo, a sign reads:
FILE - In this July 3, 2021 file photo, a sign reads: " Temporarily Closed. We have an IT-disturbance and our systems are not functioning", posted in the window of a closed Coop supermarket store in Stockholm, Sweden. The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident. Kaseya spokeswoman Dana Liedholm would not say Thursday, July 22, how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims.(Ali Lorestani/TT via AP, File)
Report Error Submit a Tip

More Stories

Leon’s Getting Larger and their tours are getting longer

Tiago Resko 4 minute read Preview

Leon’s Getting Larger and their tours are getting longer

Tiago Resko 4 minute read Yesterday at 3:00 AM CDT

Emo music was never just a phase for Nikola Boticki.

“It was people just saying the things I was feeling,” says the 26-year-old vocalist and guitarist. “Growing up, it’s kind of like, ‘I feel that way but I’m not going to say that out loud,’ so it was nice to hear someone say it.”

Boticki got into the punk subgenre near the end of his angsty high school years and his appreciation only grew while in isolation during the COVID-19 pandemic.

The music inspired him to form his own emo band, Leon’s Getting Larger, with friends Luke Penner (vocals/drums) and Noah St Hilaire (bass).

Read
Yesterday at 3:00 AM CDT

Puzzles Palace

1 minute read Monday, Jul. 27, 2026

To solve our puzzles, please subscribe with this special offer: |

Kaseya gets master decryption key after July 4 global attack

Frank Bajak, The Associated Press 5 minute read Preview

Kaseya gets master decryption key after July 4 global attack

Frank Bajak, The Associated Press 5 minute read Thursday, Jul. 22, 2021

BOSTON (AP) — The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident.

Kaseya spokeswoman Dana Liedholm would not say Thursday how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims. The cybersecurity firm Emsisoft confirmed that the key worked and was providing support.

Ransomware analysts offered multiple possible explanations for why the master key, which can unlock the scrambled data of all the attack's victims, has now appeared. They include: Kaseya paid; a government paid; a number of victims pooled funds; the Kremlin seized the key from the criminals and handed it over through intermediaries — or perhaps the main attacker didn't get paid by the gang whose ransomware was used.

The Russia-linked criminal syndicate that supplied the malware, REvil, disappeared from the internet on July 13. That likely deprived whoever carried out the attack of income because such affiliates split ransoms with the syndicates that lease them the ransomware. In the Kaseya attack, the syndicate was believed overwhelmed by more ransom negotiations than it could manage, and decided to ask $50 million to $70 million for a master key that would unlock all infections.

Read
Thursday, Jul. 22, 2021

Watching while we work

Tory McNally 7 minute read Preview

Watching while we work

Tory McNally 7 minute read 2:01 AM CDT

For many employees, the idea that their employer might be tracking how long they spend at their keyboard, how often they move their mouse, or whether they are actively working throughout the day feels unsettling. For many employers, however, workplace surveillance is increasingly viewed as another management tool, particularly as hybrid and remote work become more common. The recent news that TD plans to monitor certain employees’ activity during the workday has reignited a conversation that has been quietly growing for several years: where is the line between legitimate oversight and excessive monitoring?

The reality is that workplace surveillance is nothing new. Employers have long monitored attendance, reviewed security camera footage, tracked company vehicles using GPS, audited expense reports, and reviewed internet usage on company-owned devices. What has changed is the sophistication of the technology. Today’s software can record login times, monitor application usage, track keystrokes, capture screenshots, analyze email activity, and even generate reports ranking employees based on their perceived productivity.

This naturally raises an important question. Does increased surveillance actually make people work harder?

The answer is not nearly as straightforward as many organizations hope.

Read
2:01 AM CDT

Survival guide offers a frightening perspective on life in U.S. prisons

Reviewed by Bill Rambo 4 minute read Preview

Survival guide offers a frightening perspective on life in U.S. prisons

Reviewed by Bill Rambo 4 minute read 2:01 AM CDT

Canadian criminal sentencing guidelines identify “three traditional utilitarian goals — deterrence … incapacitation and rehabilitation.”

In spite of lofty intentions, fiction and film have identified North American incarceration in general as largely negative, incapacitating most inmates only while they are actually behind bars. Prison often leads to more crime, teaching criminal behaviour.

Tom Nelson spent more than 17 years in medium and maximum security facilities in the U.S. for such pasttimes as auto theft, armed robbery and drug dealing. Then he turned that life of crime around and became a successful physical trainer and gym owner in Los Angeles.

Nelson met and formed a friendship with Taylor Sheridan, creator and writer of such series as Yellowstone, Landman and the prequels 1883 and 1923. When COVID devastated the gym business and Nelson’s health was failing, Sheridan suggested turning Nelson’s attempt at a screenplay about prison life into a book.

Read
2:01 AM CDT

City puts Osborne Village lot up for sale third time

Joyanne Pursaga 6 minute read Preview

City puts Osborne Village lot up for sale third time

Joyanne Pursaga 6 minute read Thursday, Aug. 6, 2026

The city is making a third attempt to sell a seemingly prime Osborne Street property, after an offer for the surface parking lot fell through earlier this year.

The 772-square-metre space at 145 Osborne St., which formerly operated as an official paid city parking lot, has been posted for sale once again.

It may puzzle some Winnipeggers to see the site in the heart of Osborne Village remain empty so long after the city declared it surplus in 2020.

However, a few different challenges may limit its appeal to potential buyers, alocal real estate agent said.

Read
Thursday, Aug. 6, 2026