Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
█ Ransomware KASEYA-BLACKMAMBA- 2026-09-10

Kaseya: BlackMamba Ransomware Supply Chain Claim, Single Sourced

"A single report published 9 September 2026 alleges that IT management vendor Kaseya has been hit by a ransomware attack attributed to a group it calls BlackMamba, with downstream disruption cascading into logistics…"

A single report published 9 September 2026 alleges that IT management vendor Kaseya has been hit by a ransomware attack attributed to a group it calls BlackMamba, with downstream disruption cascading into logistics, healthcare and manufacturing customers. That report claims at least 1,500 affected organisations across North America, Europe and Asia, a $5 million per victim Bitcoin demand, and data theft used as extortion leverage. Wasteland has reviewed eight sources on this incident. Seven of them describe a different event: the July 2021 compromise of Kaseya VSA by the REvil/Sodinokibi group. No primary source in this set, meaning no Kaseya statement, no regulator filing, no vendor advisory and no national CERT bulletin, corroborates a 2026 BlackMamba intrusion. Defenders should treat the BlackMamba attribution and every figure attached to it as unconfirmed pending corroboration, while treating the underlying VSA supply chain exposure as thoroughly documented and still relevant.

What Happened

Accounts differ sharply, and the difference is the story.

The single report making the 2026 claim (Rankiteo, syndicated via MSN) states that BlackMamba, described as a ransomware-as-a-service syndicate, exploited a zero-day in Kaseya VSA to push payloads to managed endpoints. It dates the deployment to 12 July 2024, says exploit testing began in early June, and says Kaseya shipped an emergency patch on 14 July. Those internal dates do not align with a September 2026 publication or with a currently unfolding incident, which is itself a reason for caution. It reports confirmed incidents in the US, Germany, Japan and Australia, over 600 logistics firms reporting delays, and a major US hospital network diverting emergency patients after its EHR system was encrypted. None of that is corroborated elsewhere in this source set.

The corroborated event, described consistently across TheNextWeb, Acronis, Bachao.AI, a LinkedIn retrospective and Reuters reporting carried by Al Jazeera, is the attack that began late on 2 July 2021, timed to the US Independence Day weekend when staffing was thinnest. REvil exploited flaws in on-premises Kaseya VSA servers, bypassed authentication and pushed a fraudulent software update through VSA agents to MSP customer machines. Kaseya CEO Fred Voccola told Reuters on 6 July 2021 that between 800 and 1,500 businesses worldwide were affected, adding that precise impact was hard to estimate because most victims were customers of Kaseya's customers rather than Kaseya's own. Estimates in the wider set converge on roughly 1,500 downstream firms across dozens of MSPs.

On ransom, the sources conflict directly. Reuters and TheNextWeb both report REvil demanding $70 million for a universal decryptor covering all victims, with the attackers telling Reuters "we are always ready to negotiate." The 2026 Rankiteo report instead describes $5 million in Bitcoin per victim. These are different extortion models, not different estimates of the same number, and they should not be blended.

What Was Taken

For the 2021 event, the dominant impact was encryption and operational denial rather than confirmed mass data theft. Swedish retailer Coop closed roughly 800 stores after point of sale terminals froze, with the chain taking most of a week to fully reopen. Schools and kindergartens in New Zealand were knocked offline. Most direct victims were small operators, dentists' offices and accounting practices, reached through their MSP. The attackers publicly claimed a million machines compromised, a figure that was never independently substantiated and should be read as extortion posturing.

For the 2026 claim, the reporting source states data was exfiltrated and held for leak, but gives no record count, no data categories and no victim notification. There is no corroborating detail from any other source and no primary confirmation. Wasteland is not treating any exfiltration volume as established.

The relevant contrast is the MOVEit campaign of May 2023, cited in the LinkedIn retrospective, where the payload was pure theft: medical records, driver's licence numbers, Social Security numbers, pension and payroll data pulled from file transfer servers, with a large share of victims never having run the vulnerable software themselves. That is the model to expect if a modern RMM compromise recurs.

Why It Matters

The strategic lesson does not depend on resolving the attribution dispute. An RMM agent, backup console or remote access tool running inside your network on behalf of an IT vendor is a privileged, trusted channel. It is designed to install software at scale without triggering alerts. The moment it is compromised upstream, that design becomes the attacker's distribution network. If you outsource IT to an MSP, you inherit their security posture whether you audited it or not.

Kaseya 2021 and MOVEit 2023 together marked the shift from opportunistic ransomware to industrialised extortion, where compromising one vendor yields hundreds or thousands of victims in a single push. Coop was not hacked in any conventional sense. No one phished a Coop employee or cracked a Coop password. It was collateral damage from a compromise three links up its supply chain, at a vendor most of its customers had never heard of.

There is a second lesson in this brief itself. Low-quality aggregated threat reporting increasingly recycles historical incidents with fresh dates and invented actor names. A defender who actioned the BlackMamba claim without checking would be chasing an actor that has no corroborating evidence in this source set, while the genuine, KEV-listed Kaseya VSA exposure sits unpatched in the same estate.

The Attack Technique

The documented VSA attack chain is well characterised and worth mapping against your own controls:

A second, older flaw underlines that this is a recurring class rather than a one-off. CVE-2018-20753, scored CVSS v3 9.8 critical and also KEV-listed, allows unprivileged remote attackers to execute PowerShell payloads on all managed devices in Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 9.4.0.36 and R9.5 9.5.0.5. It was actively exploited in the wild in January 2018. Two separate mass-execution primitives in the same product, three years apart, both weaponised.

What Organizations Should Do

  1. Inventory every RMM and remote access agent in your estate, including ones you did not install. Anything your MSP, MDR provider or backup vendor runs inside your perimeter counts. You cannot defend a distribution channel you have not enumerated.
  2. Patch and verify against KEV, not against a maintenance calendar. Confirm Kaseya VSA is at 9.5.7 or later for CVE-2021-30116, and above the R9.3/R9.4/R9.5 thresholds for CVE-2018-20753. Both are KEV-listed with federal remediation deadlines; commercial defenders should apply equivalent urgency.
  3. Remove management consoles from the public internet. On-premises VSA-class servers should sit behind VPN or zero trust access with MFA enforced. The 2021 chain started at an internet-reachable download page.
  4. Alert on the agent itself. Build detections for RMM agents spawning PowerShell or unexpected child processes, for antivirus services being stopped, and for signed-looking binaries executing from agent working directories. The trusted process is the attack path, so trust it less.
  5. Put contractual and technical controls on your MSP. Demand evidence of MFA on their management plane, patch SLAs for RMM software, network segmentation between client tenants, and immediate notification of compromise. Ask what happens to your environment if their console is taken over tonight.
  6. Assume long-weekend timing and test offline recovery. The 2021 attack launched on a Friday before a US public holiday, deliberately. Verify that immutable or offline backups restore under skeleton staffing, and rehearse it.
  7. Do not action the BlackMamba attribution as fact. Until Kaseya, a regulator filing or a national CERT confirms a 2026 incident, treat it as an unverified claim. If your organisation has genuine indicators of a current Kaseya-linked compromise, report them upstream rather than relying on aggregated reporting.

Sources: Kaseya: MSN | CVE-2018-20753 Tenable® | REvil’s humungous $70M Kaseya ransomware attack, explained | REvil ransomware supply chain attack against MSPs | Kaseya VSA Ransomware Attack: MSP Supply-Chain Risk for India Bach... | How the Kaseya and MOVEit Attacks Industrialized Cyber Extortion | 🔴 Critical Vulnerability: CVE-2021-30116 — kaseya — vsaagent, vsase... | Up to 1,500 firms could be affected by Friday’s cyberattack: CEO A...