The Wall Street Journal: Ransomware group behind meat supply attack threatens hundreds of new targets

This post was originally published on this site

The ransomware group that collected an $11 million payment from meat producer JBS SA 
JBSS3,
+1.37%

about a month ago has begun a widespread attack that could affect hundreds of organizations world-wide, according to cybersecurity experts.

The group, known as REvil, has focused its attack on Kaseya VSA , software used by large companies and technology-service providers to manage and distribute software updates to systems on computer networks, according to security researchers and VSA’s maker, Kaseya Ltd.

The use of trusted partners like software makers or service providers to identify and compromise new victims, often called a supply-chain attack, is unusual in cases of ransomware, in which hackers shut down the systems of institutions and demand payment to allow them to regain control. The Kaseya incident appears to be the “largest and most significant” such attack to date, said Brett Callow, a threat analyst for cybersecurity company Emsisoft.

Upon learning of the attack Friday, Kaseya immediately shut down its servers and began warning customers, the company said. As of Friday evening, it said, only customers running the software on their own servers, rather than users of Kaseya’s online service, appear to have been affected.

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency advised Kaseya users to shut down their VSA servers immediately. “CISA is closely monitoring this situation and we are working with the FBI to gather information about its impact,” said Eric Goldstein, the agency’s executive assistant director for cybersecurity, in a statement.

Kaseya says that fewer than 40 of its more than 36,000 customers were affected by the incident. However, many of Kaseva’s users are service providers that, in turn, have many more customers that could have potentially been hit.

At least a dozen service providers that collectively manage the IT and security of about 1,000 customers were victims of the incident, said Kyle Hanslovan, chief executive of the security firm Huntress. Most of the customers of these providers are small and midsize organizations, he said.

Ransomware has emerged as one of the country’s most serious security problems in recent years, as hackers have targeted businesses, hospitals, schools and other institutions. Attackers have grown bolder as millions of people began using  less-secure home internet connections for work and school during pandemic lockdowns.

About a month ago, a REvil attack temporarily knocked out plants that process one-fifth of the U.S. meat supply. JBS’s U.S. unit paid $11 million in ransom to the attackers, according to a company executive.

An expanded version of this story appears on WSJ.com