In June, the U.S. Secret Service warned the private sector and government agencies that there has been a worrying increase in attacks targeting managed service providers (MSPs). MSPs provide software for companies. They can range from simple services, such as file sharing systems, to complete solutions that manage a customer’s entire computer fleet. Most services are based on the client-server software architecture model. The server can be hosted remotely with the MSP, within a leveraged infrastructure, or installed on-premise with the customer. Typically, access to the server component of an MSP gives an attacker the ability to take complete control of all of the customer’s software.
In a security alert sent out on June 12, the U.S. Secret Service said its Global Investigations Operations Center (GIOC) research team is seeing an increase in incidents where hackers are compromising MSP solutions and using them as a springboard into the internal networks of the MSP’s customers. Specifically, officials said they are seeing hackers using compromised MSPs to launch attacks against point-of-sale (POS) systems, perform business enterprise compromise (BEC) and deploy ransomware. This alert includes best practices that MSPs and their respective customers should implement. Attacks against MSPs saw a significant increase in 2019, when ransomware, such as GandCrab or REvil, began targeting MSPs and infecting their customers.

In a report published in late 2019, threat intelligence firm Armor said it had identified at least 13 MSPs that had been compromised in 2019, with their infrastructure used to deploy ransomware on their customers’ networks. Kyle Hanslovan, CEO of Huntress Labs, told ZDNet that his company supported at least 63 MSP hacking incidents in 2019 that resulted in ransomware being deployed on customers’ networks. However, Hanslovan estimates that the total number of incidents was over 100 last year.
Furthermore, ConnectWise, one of the largest MSPs in the market, has had its products and services targeted by hackers on several occasions. In November 2019, ConnectWise sent out a warning to its customers to inform them about ransomware gangs that exploited misconfigured on-premises installations of its ConnectWise Automate product to compromise customer networks and deploy file-encrypting payloads.
Additionally, in June 2020, ConnectWise patched a vulnerability in its Automate API that hackers had exploited to compromise companies and deploy ransomware. This vulnerability and its subsequent exploitation were the factors that led the U.S. Secret Service to issue its warning.

This warning was the second security alert issued by US authorities regarding attacks against MSPs. The National Cybersecurity and Communications Integration Center (NCCIC) issued the first alert in October 2018, aiming to inform about attempts by state-run hacking groups to compromise MSPs, and in particular attacks targeting cloud-based service providers.
The security alert comes at a time when Chinese hacking groups have been focusing on breaching managed cloud- based providers , aiming to compromise larger companies through their software supply chain. This is the second time the U.S. Secret Service has warned of similar attacks, but they are being carried out by everyday cybercrime gangs rather than state-sponsored hackers.
