Major cyber attack hits 200 American businesses

Share
Hundreds of American businesses were hit on Friday by a sophisticated attack that hijacked widely used technology management software from IT firm, Kaseya

Joe Biden has directed US intelligence agencies to investigate a sophisticated ransomware attack that hit hundreds of American businesses as the Fourth of July holiday weekend began. 

Huntress Labs, a cybersecurity company, said on Friday that 200 American businesses were hit after an incident at the Miami-based IT firm Kaseya. 

The hackers who struck hijacked widely used technology management software from a supplier, Kaseya, that has headquarters in Dublin and Miami. They changed a tool called VSA, used by companies that manage technology at smaller businesses, then encrypted the files of those providers’ customers.

Kaseya said it was investigating a “potential attack” on VSA, which IT professionals use to manage servers, desktops, network devices, and printers. 

 

International effects

 

The effects were felt not only in America but internationally too. In Sweden, most of the grocery chain Coop’s 800 stores were unable to open because cash registers weren’t working, according to the public broadcaster. State railways and a major pharmacy chain were also affected.

A spokeswoman for Coop Sweden told the BBC: "We first noticed problems in a small number of stores on Friday evening around 6:30pm so we closed those stores early. Then overnight we realised it was much bigger and we took the decision not to open most of our stores this morning so that our teams could work out how to fix it.

"The whole paying system at our tills and our self-service checkouts stopped working so we need time to reboot the system."

The supermarket itself was not targeted by hackers, but is one of a growing number of organisations affected by an attack on a large software supplier the company uses indirectly.

 According to a company update Saturday night, Kaseya only received a single report of a new infection Saturday from a client who left their VSA server on.

“We are confident we understand the scope of  the issue and are partnering with each client to do everything possible to remediate. We believe that there is zero related risk right now for any VSA client who is a SaaS customer or on-prem VSA customer who has their server off,” the company wrote.

 

Share

Featured Articles

How The UK’s AI Plan Will Impact The Cybersecurity Sector

The UK’s £14bn AI investment requires enhanced cybersecurity measures as Kyndryl and Vantage Data Centres prepare for infrastructure expansion

Darktrace to Acquire Cado Security in Cloud Defence Push

AI cybersecurity firm Darktrace expands its cloud investigation capabilities through purchase of Cado Security, following recent acquisition by Thoma Bravo

Sophos MDR Reports 37% Customer Growth in Cybersecurity Push

Managed detection service now protects 26,000 organisations as demand rises for round-the-clock threat monitoring and incident response capabilities

Netskope Data Shows Phishing Success Rate Tripled in 2024

Cyber Security

CrowdStrike Field CTO Warns of Identity-Based Attacks Shift

Cyber Security

Gartner: How to Align Risk Management and Governance in 2025

Operational Security