Subscribe Login
Jamaica Observer
ePaper
The Edge 105 FM Radio Fyah 105 FM
Jamaica Observer
ePaper
The Edge 105 FM Radio Fyah 105 FM
    • Home
    • News
      • Latest News
      • Cartoon
      • International News
      • Central
      • North & East
      • Western
      • Environment
      • Health
      • #
    • Business
      • Business Bites
      • Social Love
    • Sports
      • Football
      • Basketball
      • Cricket
      • Horse Racing
      • World Champs
      • Commonwealth Games
      • FIFA World Cup 2022
      • Olympics
      • #
    • Entertainment
      • Music
      • Movies
      • Art & Culture
      • Bookends
      • #
    • Lifestyle
      • Page2
      • Food
      • Tuesday Style
      • Food Awards
      • JOL Takes Style Out
      • Design Week JA
      • Black Friday
      • #
    • All Woman
      • Home
      • Relationships
      • Features
      • Fashion
      • Fitness
      • Rights
      • Parenting
      • Advice
      • #
    • Obituaries
    • Classifieds
      • Employment
      • Property
      • Motor Vehicles
      • Place an Ad
      • Obituaries
    • More
      • Games
      • Elections
      • Jobs & Careers
      • Study Centre
      • Jnr Study Centre
      • Letters
      • Columns
      • Advertorial
      • Editorial
      • Supplements
      • Webinars
    • Home
    • News
      • Latest News
      • Cartoon
      • International News
      • Central
      • North & East
      • Western
      • Environment
      • Health
      • #
    • Business
      • Business Bites
      • Social Love
    • Sports
      • Football
      • Basketball
      • Cricket
      • Horse Racing
      • World Champs
      • Commonwealth Games
      • FIFA World Cup 2022
      • Olympics
      • #
    • Entertainment
      • Music
      • Movies
      • Art & Culture
      • Bookends
      • #
    • Lifestyle
      • Page2
      • Food
      • Tuesday Style
      • Food Awards
      • JOL Takes Style Out
      • Design Week JA
      • Black Friday
      • #
    • All Woman
      • Home
      • Relationships
      • Features
      • Fashion
      • Fitness
      • Rights
      • Parenting
      • Advice
      • #
    • Obituaries
    • Classifieds
      • Employment
      • Property
      • Motor Vehicles
      • Place an Ad
      • Obituaries
    • More
      • Games
      • Elections
      • Jobs & Careers
      • Study Centre
      • Jnr Study Centre
      • Letters
      • Columns
      • Advertorial
      • Editorial
      • Supplements
      • Webinars
  • Home
  • News
    • International News
  • Latest
  • Business
    • Business Bites
  • Cartoon
  • Games
  • Food Awards
  • Health
  • Entertainment
    • Bookends
  • Regional
  • Sports
    • Sports
    • World Cup
    • World Champs
    • Olympics
  • All Woman
  • Career & Education
  • Environment
  • Webinars
  • More
    • Football
    • Elections
    • Letters
    • Advertorial
    • Columns
    • Editorial
    • Supplements
  • Epaper
  • Classifieds
  • Design Week
Fallout continues from biggest global ransomware attack
This February 23, 2019, file photo shows the inside of a computer in Jersey City, NJ.
Latest News
July 4, 2021

Fallout continues from biggest global ransomware attack

BOSTON, United States (AP) — The single biggest ransomware attack yet continued to bite Monday as more details emerged on how a Russia-linked gang breached the exploited software company. The criminals essentially used a tool that helps protect against malware to spread it globally.

Thousands of organizations — largely firms that remotely manage the IT infrastructure of others — were infected in at least 17 countries in Friday’s assault. Kaseya, whose product was exploited, said Monday that they include several just returning to work.

Because the attack by the notorious REvil gang came just as a long Fourth of July weekend began, many more victims were expected to learn their fate when they return to the office Tuesday.

REvil is best known for extorting US$11 million from the meat processor JBS last month. Security researchers said its ability to evade anti-malware safeguards in this attack and its apparent exploitation of a previous unknown vulnerability on Kaseya servers reflect the growing financial muscle of REvil and a few dozen other top ransomware gangs whose success helps them afford the best digital burglary wares. Such criminals infiltrate networks and paralyze them by scrambling data, extorting their victims.

REvil was seeking US$5 million payouts from the so-called managed service providers that were its principal downstream targets in this attack, apparently demanding much less — just US$45,000 — from their afflicted customers.

But late Sunday, it offered on its dark web site to make available a universal decryptor that would unscramble all affected machines if it’s paid US$70 million in cryptocurrency. Some researchers considered the offer a PR stunt, while others thought it indicates the criminals have more victims than they can manage.

Sweden may be hardest hit — or at least most transparent about the damage. Its defence minister, Peter Hultqvist, bemoaned in a TV interview “how fragile the system is when it comes to IT security.” Most of the Swedish grocery chain Coop’s 800 stores were closed for a third day, their cash registers crippled. A Swedish pharmacy chain, gas station chain, the state railway and public broadcaster SVT also were hit.

A wide array of businesses and public agencies were affected, including in financial services and travel, but few large companies were hit, the cybersecurity firm Sophos said. The United Kingdom, South Africa, Canada, Argentina, Mexico, Indonesia, New Zealand and Kenya were among countries affected, researchers said.

In a statement Sunday, deputy US national security adviser Anne Neuberger urged all victims to alert the FBI. A day earlier, the FBI said in an alert that the attack’s scale “may make it so that we are unable to respond to each victim individually.”

The vast majority of ransomware victims are loathe to publicly admit it, and many avoid reporting attacks to law enforcement or disclosing if they pay ransoms unless required by law.

President Joe Biden said Saturday that he ordered a “deep dive” by US intelligence into the attack and that the US would respond if it determines the Kremlin is involved. In Geneva last month, Biden sought to pressure Russian President Vladimir Putin to end safe haven for REvil and other ransomware gangs that operate with impunity in Russia and allied states as long as they avoid domestic targets. The syndicates’ extortionary attacks have worsened in the past year.

On Monday, Putin spokesman Dmitry Peskov was asked if Russia was aware of the attack or had looked into it. He said no but suggested it could be discussed during US-Russian consultations on cybersecurity issues. No date has been set for such consultations, and few analysts expect the Kremlin to crack down on a crime wave that benefits Putin’s strategic objectives of destabilizing the West.

Kaseya said Monday that fewer than 70 of its 37,000 customers were affected, though most were managed service providers with multiple downstream customers. Most managed service providers were apt to know by Monday if they were hit but that may not be true for many of the small and medium-sized organizations they serve, said Ross McKerchar, chief information security officer at Sophos. The MSPs are flying blind because the very software tool they use to monitor customer networks was knocked out by the attack.

The hacked Kaseya tool, VSA, remotely maintains customer networks, automating security and other software updates.

In a Monday report on the attack, Sophos said a VSA server was breached with the apparent use of a “zero day,” the industry term for a previously unknown software security hole. Like other cybersecurity firms, it faulted Kaseya for aiding the attackers by asking customers not to monitor its on-premise “working” folders for malware. From inside those folders, REvil’s code could work undetected to disable the malware- and ransomware-flagging tools of Microsoft’s Defender program.

Sophos said REvil made no attempt to steal data in this attack. Ransomware gangs usually do that before activating ransomware so they can threaten to dump it online unless they are paid. This attack was apparently bare bones, only scrambling data.

In a Sunday interview, Kaseya CEO Fred Voccola would not confirm the use of a zero day or offer details of the breach — except to say that it was not phishing and that he was confident that when an investigation by the cybersecurity firm is complete, it would show that not just Kaseya but third-party software were breached by the attackers.

{"website":"website"}{"jamaica-observer":"Jamaica Observer"}
img img
0 Comments · Make a comment

ALSO ON JAMAICA OBSERVER

Trump says Israel, Lebanon agree to 10-day ceasefire
International News, Latest News
Trump says Israel, Lebanon agree to 10-day ceasefire
April 16, 2026
WASHINGTON, United States (AFP)—United States (US) President Donald Trump announced that Israel and Lebanon have agreed to a 10-day ceasefire starting...
{"jamaica-observer":"Jamaica Observer"}
NWA begins paving of temporary bypass after breakaway in Belmont, Westmoreland
Latest News, News
NWA begins paving of temporary bypass after breakaway in Belmont, Westmoreland
April 16, 2026
WESTMORELAND, Jamaica — The National Works Agency (NWA) has commenced the paving of a temporary route for a section of the Belmont main road in Westmo...
{"jamaica-observer":"Jamaica Observer"}
Usain Bolt revealed as Hublot ambassador with new limited-edition watch
Latest News, Sports
Usain Bolt revealed as Hublot ambassador with new limited-edition watch
April 16, 2026
Usain Bolt and Hublot have partnered to release a limited-edition timepiece bearing tributes to the legendary sprinter. Only 200 versions of the Hublo...
{"jamaica-observer":"Jamaica Observer"}
Messi buys Spanish soccer club Cornella
International News, Latest News
Messi buys Spanish soccer club Cornella
April 16, 2026
BARCELONA, Spain (AFP)—Lionel Messi has bought Catalan club Cornella and become the team's new owner, the Spanish fifth-tier side announced on Thursda...
{"jamaica-observer":"Jamaica Observer"}
450, Popcaan set to perform in stacked line-up at Barbados Reggae Weekend 2026
Entertainment, Latest News
450, Popcaan set to perform in stacked line-up at Barbados Reggae Weekend 2026
April 16, 2026
BRIDGETOWN, Barbados — Jamaican reggae and dancehall superstars, including 450, Popcaan, Dexta Daps and Sister Nancy, will take the stage along with B...
{"jamaica-observer":"Jamaica Observer"}
Black River police issue high alert for UK child allegedly abducted and brought to Jamaica
Latest News, News
Black River police issue high alert for UK child allegedly abducted and brought to Jamaica
April 16, 2026
ST ELIZABETH, Jamaica — St Elizabeth police have activated a high alert for a British six-year-old girl whose mother says she has been abducted by her...
{"jamaica-observer":"Jamaica Observer"}
Sports lawyer questions World Athletics’ move to refuse Jamaican athletes transfer to Turkey
Latest News, Sports
Sports lawyer questions World Athletics’ move to refuse Jamaican athletes transfer to Turkey
April 16, 2026
KINGSTON, Jamaica — Noted sports lawyer Dr Emir Crowne has questioned the procedural fairness of World Athletics’ decision on Thursday to refuse the t...
{"jamaica-observer":"Jamaica Observer"}
Former Virginia Lt Gov Justin Fairfax and wife found dead in suspected murder-suicide
International News, Latest News
Former Virginia Lt Gov Justin Fairfax and wife found dead in suspected murder-suicide
April 16, 2026
Former Virginia Lieutenant Governor Justin Fairfax reportedly shot and killed his wife, Cerina, on Thursday inside the couple's Virginia home and then...
{"jamaica-observer":"Jamaica Observer"}
❮ ❯

Polls

HOUSE RULES

  1. We welcome reader comments on the top stories of the day. Some comments may be republished on the website or in the newspaper; email addresses will not be published.
  2. Please understand that comments are moderated and it is not always possible to publish all that have been submitted. We will, however, try to publish comments that are representative of all received.
  3. We ask that comments are civil and free of libellous or hateful material. Also please stick to the topic under discussion.
  4. Please do not write in block capitals since this makes your comment hard to read.
  5. Please don't use the comments to advertise. However, our advertising department can be more than accommodating if emailed: advertising@jamaicaobserver.com.
  6. If readers wish to report offensive comments, suggest a correction or share a story then please email: community@jamaicaobserver.com.
  7. Lastly, read our Terms and Conditions and Privacy Policy

Recent Posts

Archives

Facebook
Twitter
Instagram
Tweets

Polls

Recent Posts

Archives

Logo Jamaica Observer
Breaking news from the premier Jamaican newspaper, the Jamaica Observer. Follow Jamaican news online for free and stay informed on what's happening in the Caribbean
Featured Tags
  • Editorial
  • Columns
  • Health
  • Auto
  • Business
  • Letters
  • Page2
  • Football
Categories
  • Business
  • Politics
  • Entertainment
  • Page2
  • Business
  • Politics
  • Entertainment
  • Page2
Ads
img
Jamaica Observer, © All Rights Reserved
  • Home
  • Contact Us
  • RSS Feeds
  • Feedback
  • Privacy Policy
  • Editorial Code of Conduct