Kaseya gets master decryption key after July 4 global attack

By FRANK BAJAK
AP Technology Writer

BOSTON (AP) — The Florida company whose software was exploited in the devastating Fourth of July weekend ransomware attack, Kaseya, has received a universal key that will decrypt all of the more than 1,000 businesses and public organizations crippled in the global incident.

Kaseya spokeswoman Dana Liedholm would not say Thursday how the key was obtained or whether a ransom was paid. She said only that it came from a “trusted third party” and that Kaseya was distributing it to all victims. The cybersecurity firm Emsisoft confirmed that the key worked and was providing support.

Ransomware analysts offered multiple possible explanations for why the master key, which can unlock the scrambled data of all the attack’s victims, has now appeared. They include: Kaseya paid; a government paid; a number of victims pooled funds; the Kremlin seized the key from the criminals and handed it over through intermediaries — or perhaps the main attacker didn’t get paid by the gang whose ransomware was used.

The Russia-linked criminal syndicate that supplied the malware, REvil, disappeared from the internet on July 13. That likely deprived whoever carried out the attack of income because such affiliates split ransoms with the syndicates that lease them the ransomware. In the Kaseya attack, the syndicate was believed overwhelmed by more ransom negotiations than it could manage, and decided to ask $50 million to $70 million for a master key that would unlock all infections.

By now, many victims will have rebuilt their networks or restored them from backups.

It’s a mixed bag, Liedholm said, because some “have been in complete lockdown.” She had no estimate of the cost of the damage and would not comment on whether any lawsuits may have been filed against Kaseya. It is not clear how many victims may have paid ransoms before REvil went dark.

The so-called supply-chain attack of Kaseya was the worst ransomware attack to date because it spread through software that companies known as managed service providers use to administer multiple customer networks, delivering software updates and security patches.

President Joe Biden called his Russian counterpart, Vladimir Putin, afterward to press him to stop providing safe haven for cybercriminals whose costly attacks the U.S. government deems a national security threat. He has threatened to make Russia pay a price for failing to crack down, but has not specified what measures the U.S. may take.

If the universal decryptor for the Kaseya attack was turned over without payment, it would not be the first time ransomware criminals have done that. It happened after the Conti gang hobbled Ireland’s national health care service in May and the Russian Embassy in Dublin offered “to help with the investigation.”

SportsPlus

McNeese Sports

Cowboys upset No. 25 Weber State

Local News

Hezbollah confirms its leader Hassan Nasrallah was killed in an Israeli airstrike

Jim Beam

Jim Beam column:Why are groceries so high?

Local News

State superintendent: La. education system moving ‘in right direction’

Local News

DeRidder man killed in single-vehicle crash

life

Volunteers at Second Harvest warehouse bag groceries for distribution

life

SW La. nightlife calendar: There’s always something to do

life

Jeff Davis Parish Fair focuses on fun, families

Local News

Rescuers race to free people trapped by Hurricane Helene after storm kills at least 35 in 4 states

life

McNeese Library to host rare book petting zoo 

Crime

9/27: Calcasieu Parish Sheriff announces arrest list

life

Slime time: Three hours of fun, food, movies planned for Nickelodeon Day of Play at Prien Lake Park

life

On the wild side: ‘Hit Me with Your Best shot’ exhibit showcases birds in their natural habitat

Local News

Cowboys start long road stretch

Local News

Teacher Alicia Chism: ‘Every student has the potential to succeed’

Local News

H.C. Drew School of Kinesiology showcases education, opportunities it offers

Local News

United Way leads disaster relief for Helene victims

Local News

Helene makes landfall as Category 4 hurricane

Local News

Landlords need renters, the parish has them

Local News

Louisiana Fortify Homes Program doubles number of grants to be awarded from 300 to 600

Crime

Sheriff: LC man fatally shoots neighbor, calls 911

Crime

Third suspect sought in fatal Rena Street shooting

Jim Gazzolo

Jim Gazzolo column: Schedule offers no rewards

McNeese Sports

Boogsie man: Silvera scary to offenses