REvil affiliates exploited a SQL injection zero-day in Kaseya's VSA remote-management platform to push ransomware to ~60 MSPs and through them to ~1,500 downstream organisations. The largest supply-chain ransomware attack on record.
- Victim
- Kaseya VSA customers (~60 MSPs, ~1,500 downstream organisations)
- Loss
- $200.0M
REvil affiliates encrypted the world's largest meat processor, shutting down beef and pork plants across the U.S., Canada, and Australia. JBS paid an $11 million ransom โ one of the largest publicly-confirmed ransomware payments at the time.
- Victim
- JBS S.A. / JBS USA
- Loss
- $100.0M
REvil/Sodinokibi operators detonated against Travelex on New Year's Eve 2019 after dwelling in the network for six months via an unpatched Pulse Secure VPN. Travelex paid $2.3 million; parent Finablr failed; PwC put Travelex into administration with the loss of over 1,300 jobs.
- Victim
- Travelex
- Loss
- $2.3M