https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Cybersecurity Roundup

Cybersecurity Roundup: MSP Survives Ransomware Attack via ConnectWise, Kaseya Tools

  • Written by Edward Gately
  • January 21, 2020
MSPs are fighting a losing battle when it comes to cyberattacks.

The number of ransomware attacks on MSPs mounted last year and more are likely to be targeted in 2020.

Dark Cubed, which provides cybersecurity solutions, procured a research study with data revealing that MSPs are fighting a losing battle when it comes to cyberattacks. MSP networks are under a barrage of attacks from malicious threat actors, and 100% of MSPs reviewed suffered either automated attacks, directed attacks or both.

To get a firsthand account of an MSP ransomware attack, we spoke with Darin Harris, COO of Remote Techs, which incurred a ransomware attack last year that nearly drove it out of business. The MSP works with clients across the western United States, and construction and transportation are its two biggest verticals.

Channel Futures: How did the ransomware attack unfold?

Darin Harris: We used two pieces of software that are very common in the industry. We used a remote management and remediation tool [from] Kaseya and then we used a ticketing and billing system [from] ConnectWise. ConnectWise had a plug-in essentially that connected the workstation data, the audit data back into ConnectWise so that you could connect tickets to workstations and things of that nature. They released a patch [at] the end of 2017 or the early part of 2018 that was to fix a vulnerability. We applied the patch, thinking we were safe, and then in … the early part of February of 2019, the exploit that existed and that was supposedly patched started to be used in the wild, and ConnectWise and Kaseya started to see MSPs becoming attacked. What it would do is essentially bypass your two-factor security, bypass your user passwords … to a direct sequel injection into the database to change a password, they would log in and then they would use Kaseya to start installing their ransomware using your servers to push the ransomware to all of the clients that were connected. Yeah, real friendly stuff.

So for us, it started at about 2:45 p.m. on a Sunday, and we have some customers that run pretty close to 24 hours a day, and so we started to get a few phone calls about 3:15 p.m. of servers being unavailable for one of our clients. We started to investigate and found clients that were ransomed. And we started to see that affect a couple of clients at the same time, at which point we quickly deduced that the issue was the Kaseya server itself. We looked into that and found that we couldn’t gain access to it like we used to be able to. And so we quickly took it offline, shut it down and then started the remediation process to fix everything. That was probably a good, solid, six-to-eight weeks, and we had – compared to other owners like myself that I’ve spoken to – manageable damage. We had about 14-16% of our connected devices become encrypted and more than half of those were servers. I know some owners and some other MSPs that had 100% encryption rate. Every single device was encrypted before they found out what was going on. So yeah, that was January. It took us two months to get everything kind of back to normal. We had our customers back up within just a few days, but … even if you can recover workstations and desktops, and servers you still have to go back and back up all the data, rebuild it from scratch and …

  • Page 1
  • Page 2
  • Page 3
  • Page 4
Tags: MSPs Business of Security Cloud and Edge Endpoint MSSP Insider Security

Most Recent


  • Mergers acquisitions m&a goldfish crackers
    Latest M&A: IBM, Vonage, Nokia, GoTo, Nitel, Ensono, Huntress, More
    One cybersecurity company's $22 million July acquisition was its largest to date.
  • Why DevOps Teams Need Security Skills and How Shift Left Tools Help
    Developers need cloud-native security skills and tools to build secure code from the start to mitigate risks.
  • Kim Zetter at Black Hat
    Black Hat USA: No Excuses for Cyberattacks to Catch Critical Infrastructure Off Guard
    Critical infrastructure remains just as vulnerable as it was years ago.
  • Partner Program Changes
    Partner Program Updates: Microsoft, TD Synnex, AppSmart, Cisco, Verizon
    Verizon is pushing channel integration big-time, and Microsoft appointed a chief partner officer.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • White House
    White House to Private Sector SMEs: Get Serious About Cybersecurity
  • zero trust security
    Leveraging Partner Expertise to Build a Zero-Trust Strategy
  • Security Vulnerability
    Older Fortinet Vulnerabilities Lead to Attack on Local Government Office
  • Threats
    Cybersecurity and Threat Protection: MSSPs, Get Your Advice Here

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Latest M&A: IBM, Vonage, Nokia, GoTo, Nitel, Ensono, Huntress, More

August 12, 2022

Partner Program Updates: Microsoft, TD Synnex, AppSmart, Cisco, Verizon

August 11, 2022

Channel Futures and Channel Partners Ready Trio of Powerhouse Summits

August 11, 2022

Industry Perspectives

View all

How to Take Shared Responsibility for Securing Cloud

August 11, 2022

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

ThreatLocker Preaches Zero Trust, Addresses Industry Competition

ScienceLogic Debuts New Partner Portal

August 9, 2022

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

June 27, 2022

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Twitter

ChannelFutures

Huge channel-impacting acquisitions in the past month. We've got details on @IBM, @nokia, @GoTo, @EnsonoIT,… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Boost privacy by design with #shiftleft mindset and add #security to cloud deployments from start, says… twitter.com/i/web/status/1…

August 12, 2022
ChannelFutures

Say sayonara to contract renewals - @KaseyaCorp responds to mounting customer concerns with significant changes.… twitter.com/i/web/status/1…

August 11, 2022
ChannelFutures

.@Kyndryl, @Five9 partnership will focus on cloud-based #contactcenter solutions. dlvr.it/SWTFPx https://t.co/WGQedUjSB1

August 11, 2022
ChannelFutures

How cloud providers and customers can work together to safely share and secure responsibility in the cloud. @Cisco… twitter.com/i/web/status/1…

August 11, 2022
ChannelFutures

See the latest updates from @verizonbusiness, @GetNerdio, @AppSmartcom, @CiscoPartners and other companies.… twitter.com/i/web/status/1…

August 11, 2022
ChannelFutures

.@nutanix said to lay off 4% of workforce by October, as company cites macroeconomic issues. dlvr.it/SWSMDN https://t.co/w6JeqkI7r6

August 11, 2022
ChannelFutures

#BHUSA Day 1 with Chris Krebs, @cybereason, @keepersecurity, @BreachQuest, @awscloud and @splunk. #cybersecurity… twitter.com/i/web/status/1…

August 11, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X