NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: When leaving IT to the pros went sideways

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
6 Jul, 2021 05:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

"Temporarily Closed. We have an IT-disturbance and our systems are not functioning." Swedish grocery chain Coop was hit hard by the Kaseya attack. Photo / AP

"Temporarily Closed. We have an IT-disturbance and our systems are not functioning." Swedish grocery chain Coop was hit hard by the Kaseya attack. Photo / AP

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

OPINION:

Hands up everyone who had heard of Kaseya before the weekend ransomware attack?

Non-geeks might assume it's the name of a dairy or cheese produce outfit, but no, it's a company that makes remote monitoring and management software or RMM.

Kaseya's Virtual System Administrator (VSA) RRM is used by Managed Service Providers or MSPs, which makes for an acronym soup but describes a model whereby businesses outsource their IT needs to shops that specialise in the verisame.

Advertisement
Advertise with NZME.

Why? Because setting up and keeping on top of rapidly changing IT environments isn't easy.

You need dedicated and experienced staff who are hard to find for that and they need costly resources and funding.

If IT isn't your core business, outsourcing the geeky stuff to an MSP makes sense. They should be able to keep software and hardware up to date, which in today's threat-dense interconnected world is an absolute requirement.

If you run your own systems and miss a patch on the ones that are reachable from the internet, chances are that it's game over for your organisation. Digital criminals and other miscreants scan for internet connected services with known flaws or which are misconfigured.

Advertisement
Advertise with NZME.

The above is all good and great until something goes wrong like it did with Kaseya last Saturday. It's a developing story and security researchers haven't yet worked out all the details but an associate of the REvil ransomware criminals managed to subvert an auto update for Kaseya VSA instances that MSPs were running themselves.

Indications so far are that the attackers didn't have to do anything particularly clever, and were able to simply exploit a file upload vulnerability.

Auto-updates are great until they're not. Especially not when they contain REvil ransomware and are being distributed to a yet to be established number of MSP customers all in one go.

One reason the attack was so successful is that as noted by security researchers, Kaseya's VSA software required specific folders on the computers to be excluded from anti malware scanners.

This is done for a range of reasons, mainly to avoid performance slowdowns as the anti-virus utilities open lots of files to scan. Kind of legit, but it did mean that the folders into which the REvil encryptor and scripts were dropped weren't scanned for malware.

Keeping software and hardware up to date in today's threat-dense interconnected world is an absolute requirement. Photo / 123RF
Keeping software and hardware up to date in today's threat-dense interconnected world is an absolute requirement. Photo / 123RF

Maybe the criminals knew this, maybe not. Either way, there was nothing to stop the malware from encrypting user files. To make doubly sure that the attack would go undetected, the attackers ran scripts to quietly hobble the built-in Microsoft Defender anti-malware system as well.

Victims hit include businesses small and large in 17 countries, like some schools in New Zealand and the Swedish Coop grocery chain which had to close hundreds of stores. REvil claims the Kaseya attack encrypted over a million systems. This seems like an empty boast and there have been no indications yet as to the actual numbers.

However, in Australia, one MSP owned up to 300 customer sites being hit by ransomware. That's sites which often have several computers, so the number of encrypted machines is likely to be in the tens of thousands.

Advertisement
Advertise with NZME.

There are some glimmers of hope here. Apparently REvil did not copy over sensitive data from victims, although that's yet to be confirmed. The malware attack also appears not to have deleted special files in Windows, and these could be used for restoring data.

Attacks on MSPs are nothing new and there will be worse to come. Ransomware victims are paying up. This coupled with continually vulnerable IT systems ensures that the criminals' business model will remain viable for some time yet.

The irony here is that the victims didn't do anything wrong per se by leaving the management of their IT to the pros. Sleeping with one eye open, minding your networked computers to ensure that all important patches and updates were applied in a timely fashion is for the birds.

By definition, MSPs are trusted sources and there to protect their customers. The ransomware raiders however laughed at that notion, and waltzed right through the defences.

Having been burnt by anti-malware software and other expensive defence systems letting them down, to a point that their businesses are threatened, the Kaseya attack shows that whatever we're doing in terms of security is just wrong. Maybe it's time to rethink how we do IT, and shut everything down for a few days to fix up the worst of the problems?

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Opinion

Bridget Snelling: How financial education can transform NZ's small-business landscape

20 Jun 03:00 AM
Premium
Media Insider

Court writer: Polkinghorne pitches his own book; TVNZ v Sky in Olympics showdown

20 Jun 01:00 AM
Premium
Property

'Māori are long-term investors' - learning from success and failure working with iwi

20 Jun 12:00 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Bridget Snelling: How financial education can transform NZ's small-business landscape

Bridget Snelling: How financial education can transform NZ's small-business landscape

20 Jun 03:00 AM

OPINION: Improving financial literacy is vital for New Zealand's small businesses to grow.

Premium
Court writer: Polkinghorne pitches his own book; TVNZ v Sky in Olympics showdown

Court writer: Polkinghorne pitches his own book; TVNZ v Sky in Olympics showdown

20 Jun 01:00 AM
Premium
'Māori are long-term investors' - learning from success and failure working with iwi

'Māori are long-term investors' - learning from success and failure working with iwi

20 Jun 12:00 AM
Premium
50 years on the ice: How an Olympic gold medal kickstarted a couple's business

50 years on the ice: How an Olympic gold medal kickstarted a couple's business

19 Jun 11:00 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP