The criminal group behind a major ransomware attack targeting US IT firm Kaseya has demanded $70 million (£50.5 million) in Bitcoin in exchange for a universal decryptor to unlock victims' files. The REvil group claims its malware has infected one million systems, though this figure remains unverified. Confirmed victims include 500 Swedish Coop supermarkets and 11 schools in New Zealand, with two Dutch IT firms also reportedly affected.
The attack exploited a vulnerability in Kaseya's software, which is used by managed service providers to manage other companies' IT systems. While Kaseya stated fewer than 40 of its direct customers were impacted, the supply-chain nature of the attack means the total number of affected organisations could be much higher. Kaseya CEO Fred Voccola estimated the number of victims would likely be in the low thousands, including small businesses like dental practices and libraries.
Cybersecurity experts have noted the unusual demand for Bitcoin, which is easier to trace than privacy-focused cryptocurrencies like Monero. This follows the US Justice Department's recent seizure of Bitcoin paid to the DarkSide ransomware group. Tom Robinson of Elliptic observed that REvil typically prefers Monero but may have opted for Bitcoin due to practical constraints in purchasing large amounts of Monero.
Prof Ciaran Martin, founder of the National Cyber Security Centre, described the attack as 'rare, if not unprecedented' in scale and sophistication. He criticised Russia for harbouring ransomware hackers, while noting that Western nations make it too easy for gangs to receive payments. The Dutch Institute for Vulnerability Disclosure revealed it had discovered the Kaseya flaw before the attack and was working to patch it, but was beaten by REvil.



