Summary
- Environment: IT/MSP software
- Operational impact: approximately 1,500 downstream businesses hit via MSPs (e.g., Coop Sweden store closures)
- Financial impact: No financial figure is established by the reviewed source evidence
- Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.
What happened
In 2021, Kaseya VSA experienced an incident in its it/msp software environment. The retained source describes the attack path as follows: REvil; zero-day in VSA supply chain. [1]
The documented consequence was: approximately 1,500 downstream businesses hit via MSPs (e.g., Coop Sweden store closures). [1]
Impact
- Documented impact: approximately 1,500 downstream businesses hit via MSPs (e.g., Coop Sweden store closures). [1]
- No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.
Threat Group & Attack Vector
The retained source describes the attack path as follows: REvil; zero-day in VSA supply chain. The canonical record does not add intrusion steps beyond those supported by the source. [1]
Actors
- REvil — identified in the supported attack description. [1]
TTPs
- T1195 — Supply Chain Compromise — mapped from the cited behavior. [1]
- T1190 — Exploit Public-Facing Application — mapped from the cited behavior. [1]
Response
The retained source describes containment action intended to limit further access or disruption. [1]
This account is bounded to Kaseya Responds Swiftly to Sophisticated Cyberattack. Details absent from that evidence are left unresolved rather than inferred. [1]
