{"id":309049,"date":"2021-07-27T08:03:16","date_gmt":"2021-07-27T05:03:16","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/kaseya-recovers-data-stolen-in-ransomware-attack-with-mysterious-decryption-tool\/"},"modified":"2021-07-27T08:03:16","modified_gmt":"2021-07-27T05:03:16","slug":"kaseya-recovers-data-stolen-in-ransomware-attack-with-mysterious-decryption-tool","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/kaseya-recovers-data-stolen-in-ransomware-attack-with-mysterious-decryption-tool\/","title":{"rendered":"# Kaseya recovers data stolen in ransomware attack with mysterious decryption tool"},"content":{"rendered":"<p>&#8220;<strong># Kaseya recovers data stolen in ransomware attack with mysterious decryption tool <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMDcvNmFjODkxZGItMDAwZS00ZjI3LWFjOTctNTFmZGIzYmRlMDBjLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>IT software provider, Kaseya, has announced it is providing its clients with a decryption tool to recover customer data that was locked in a ransomware attack earlier this month.<\/p>\n<p>In a July 26\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.kaseya.com\/potential-attack-on-kaseya-vsa\/\">notice<\/a> on its website, the global <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">technology<\/a> firm stated it has been assisting its customers with the restoration of their encrypted data in partnership with cybersecurity company Emsisoft.<\/p>\n<p>It has been issuing a mysterious \u201cdecryptor\u201d tool enabling customers to access data that had been locked by the malware disseminated in the July 2 attack.<\/p>\n<blockquote><p>\u201cThe decryption tool has proven 100% effective at decrypting files that were fully encrypted in the attack.\u201d<\/p><\/blockquote>\n<p>The company has denied paying the $70 million in Bitcoin to the Russian hacker group, REvil \u2014 which took responsibility for the attack. Kaseya did not disclose how it came across the decryption software either, stating only that has not paid any ransom to get it.<\/p>\n<p>Kaseya confirmed that, after consultation with experts, it decided not to negotiate with the criminals who perpetrated the attack, stating:<\/p>\n<blockquote><p>\u201cWe are confirming in no uncertain terms that Kaseya did not pay a ransom \u2013 either directly or indirectly through a third party \u2013 to obtain the decryptor.\u201d<\/p><\/blockquote>\n<p>On July 2, the ransomware hacking group REvil brought the networks of at least 200 U.S. companies to their knees by leveraging an unpatched zero-day vulnerability in Kaseya&#8217;s IT management and automation software (VSA).<\/p>\n<p><strong><em>Related:<\/em><\/strong><em> <\/em><em>Don\u2019t blame crypto for ransomware<\/em><\/p>\n<p>The <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a> comes as ransomware is coming under increasing scrutiny from lawmakers.<\/p>\n<p>According to a July 9 Cointelegraph report, Michele Korver\u2019s <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ointment to the U.S. Financial Crimes Enforcement Network (FinCEN) promises to reduce illicit financial practices within the crypto space. During her previous tenure at the Department of Justice, she developed cryptocurrency seizure and forfeiture policy and legislation.<\/p>\n<p>U.S. senators and politicians have come down hard on the cryptocurrency sector, largely blaming the technological phenomenon for the increase in ransomware attacks. Following the Colonial Pipeline and JBS attacks in May and June, there were calls for a crackdown on cryptocurrency in the U.S. senate after digital assets were dubbed the \u201cransom payment of choice\u201d for hackers.<\/p>\n<p>Meatpacker JBS paid an $11 million Bitcoin ransom to REvil, while Colonial made a $4.4 million BTC payment to Russia-linked DarkSide. <\/p>\n<p><template data-name=\"subscription_form\" data-type=\"law_decoded\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more News articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/kaseya-recovers-data-stolen-in-ransomware-attack-with-mysterious-decryption-tool\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Kaseya recovers data stolen in ransomware attack with mysterious decryption tool &#8221; IT software provider, Kaseya, has announced it is providing its clients with a decryption tool to recover customer data that was locked in a ransomware attack earlier this month. In a July 26\u00a0notice on its website, the global technology firm stated it&#8230;<\/p>\n","protected":false},"author":1,"featured_media":309050,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMDcvNmFjODkxZGItMDAwZS00ZjI3LWFjOTctNTFmZGIzYmRlMDBjLmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[5056,70944,73240,4965],"class_list":["post-309049","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-encryption","tag-hackers","tag-ransomware","tag-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/309049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=309049"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/309049\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/309050"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=309049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=309049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=309049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}