Multi-CloudIncident TeardownsRetrospectives

Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.

On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and management tool used by managed service providers (MSPs). Through those MSPs, ransomware reached their customers.

How it worked

Kaseya VSA lets MSPs manage and update thousands of client computers. Attackers exploited vulnerabilities in on-premises VSA servers to push a malicious "update" to managed endpoints, which deployed ransomware. Kaseya said about 60 of its direct customers (mostly MSPs) were affected, and up to around 1,500 downstream businesses. In Sweden, a grocery chain closed hundreds of stores because its point-of-sale systems were hit.

Response

Kaseya urged customers to shut down on-premises VSA servers and took its SaaS service offline as a precaution. A universal decryptor was later obtained and distributed. A suspect was later arrested and convicted in the US.

Why it mattered

The attack showed how much trust organizations place in MSPs and their tools. An MSP's management platform often has administrative access to every client device — and, increasingly, to clients' Microsoft 365 tenants. Compromise one tool, and you reach many businesses at once.

Lessons in hindsight

  • Know what access your MSP has — on devices and in your cloud tenant.
  • Limit MSP privileges in Microsoft 365 using granular delegated admin privileges (GDAP) instead of broad, permanent admin rights.
  • Require MFA and security standards from MSPs contractually.
  • Monitor MSP activity in your environment.
  • Holiday timing is deliberate. Plan response coverage for long weekends.

In hindsight

Kaseya accelerated changes in how Microsoft handles partner access. Legacy delegated admin privileges, which gave partners Global Administrator in customer tenants, were replaced by GDAP with time-limited, least-privilege roles.

kaseya ransomware attackKaseya2021

More on this story