Security News > 2021 > July > REvil ransomware asks $70 million to decrypt all Kaseya attack victims

REvil ransomware asks $70 million to decrypt all Kaseya attack victims
2021-07-05 08:59

REvil ransomware has set a price for decrypting all systems locked during the Kaseya supply-chain attack.

Customers of multiple MSPs have been impacted by the attack, REvil ransomware encrypting networks of at least 1,000 businesses across the world.

Previously, REvil ransomware asked $5 million from MSPs for a decryption tool and a $44,999 ransom from their customers.

For victims with locked files that have multiple extensions following the REvil ransomware encryption, the gang's demand can be as high as $500,000, BleepingComputer learned.

REvil was able to pull this massive attack by exploiting a zero-day vulnerability in Kaseya VSA server that had been reported privately and was in the process of being fixed.

The full extent of this REvil ransomware attack remains unclear at the moment but the incident has triggered strong reactions from law enforcement, with the FBI announcing that they are working with CISA during their investigation.


News URL

https://www.bleepingcomputer.com/news/security/revil-ransomware-asks-70-million-to-decrypt-all-kaseya-attack-victims/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Kaseya 6 0 5 14 13 32