Statement From Datto CISO Ryan Weeks

"We are still gathering facts on this incident to share with the community. At this time, we know for certain that the attacker accessed the BCDR appliances from the local network successfully on first login attempt. How the local networks were accessed by the attacker is an active line of investigation that is ongoing. When we learn more and establish the facts, and can share them, we will update you.
To significantly increase your resilience to targeted MSP ransom attacks, please follow this previously issued guidance: https://www.datto.com/best-practices-for-a-secure-bcdr. Most importantly, please enable 2FA for everyone of your employees on all your channel technology solutions and disable local WebUI access on BCDR appliances (portal access only).
We do not tolerate bad outcomes for our partners. In addition to our commitment to deploy required 2FA for Datto RMM after actioning partner feedback, we’re developing new tools and capabilities across our product stack to further reduce the likelihood and/or impact of a successful MSP attack such as this and others.
More than ever, we’re collaborating with other channel vendors and MSPs to pool intelligence that will enable us to better protect you and increase transparency."
Hackers Disable MSP Backups: Growing Trend
The attack mentioned above isn't unique. MSPs in North America, Europe and Australia have suffered hacker attacks that disable backup systems and spread ransomware across end-customer systems, ChannelE2E reported in early August 2019.In a typical scenario, the ransomware attacks spread from MSP systems to end-customer networks. When the MSP attempts a data restore, the service provider discovers BDR systems were disabled days, weeks or even months before the ransomware attack occurred, sources say. The net result, in some cases: Encrypted MSP and customer systems, and outdated or deleted backups.In some cases, the backup provider has archived systems (a backup of the backup) to assist the MSP with longer-term recoveries. But even in that scenario, the archived backup may be a bit dated.Ransomware Attacks Hit Multiple CSPs, MSPs
Ransomware attacks have hit multiple service providers in recent months. Victims include:- A cloud service provider (CSP) that works closely with MSPs.
- Data Resolution, an MSP in California.
- Multiple organizations that paid a combined $640,000 in Bitcoin over a two-week span in 2018, according to master MSSP Perch Security.