Attacks On Managed Service Providers
| Context | Attacks on Managed Service Providers |
|---|---|
| Primary target | MSPs and their clients |
| Common attack vector | Compromise of remote monitoring and management tools |
| Primary goal | Lateral movement to client networks |
| Key control principle | Principle of least privilege for MSP administrative access |
| Original use | Legitimate IT infrastructure management and support |
Origin and history
The strategic targeting of Managed Service Providers (MSPs) by threat actors originated in the late 2010s, with significant documentation and public awareness emerging around the turn of the 2020s. This operational shift was largely driven by advanced persistent threat (APT) groups affiliated with nation-states, particularly those from Russia and China, though criminal ransomware gangs later adopted the tactic. The historical context involves the increasing reliance of businesses, especially small and medium-sized enterprises, on MSPs for their entire IT infrastructure. Early publicized incidents, such as the campaigns against MSP software in 2019, demonstrated the method's effectiveness for large-scale, distributed compromise. The history of these attacks is not of a single vulnerability but of a persistent campaign strategy that exploits trust and centralized access. This approach has evolved from targeted espionage to a primary vector for ransomware deployment across broad sectors including healthcare, finance, and local government.
What it is for
The primary purpose of attacking a Managed Service Provider is to achieve a force multiplier effect, compromising one entity to gain unauthorized access to the networks of all its clients. This tactic is designed for efficiency, allowing a threat actor to bypass the individual security perimeters of dozens or hundreds of end-customer organizations simultaneously. For nation-state actors, the goal is often espionage, enabling the stealthy collection of intellectual property or sensitive data from a diverse portfolio of targets through a single point of entry. For financially motivated criminal groups, the objective is typically to deploy ransomware or other malware across the entire client base to maximize extortion payouts. The strategy also serves to obscure the attacker's ultimate targets, as investigative focus may initially center on the MSP itself. Furthermore, compromising an MSP provides access to highly privileged credentials and tools designed for system administration, which are then weaponized against downstream clients.
Overview
An attack on a Managed Service Provider is a supply chain attack that targets the provider's management and monitoring tools, remote access software, and privileged accounts. The compromise typically begins with an initial breach of the MSP's own internal systems, often via phishing, exploitation of unpatched software, or stolen credentials. Once inside the MSP network, attackers move laterally to gain control of the Remote Monitoring and Management (RMM) platforms, PSA (Professional Services Automation) tools, or cloud administration consoles used to service clients. With control of these administrative tools, the attacker can push malicious scripts, deploy ransomware payloads, or create new backdoor accounts directly onto client systems. The overview of this threat landscape includes the critical understanding that client security is now intrinsically linked to the security posture of their service provider. A successful attack fundamentally breaks the trust model between the MSP and its clients, turning a service designed for efficiency and security into a potent weapon for widespread intrusion.
What to know
It is crucial to know that an organization's risk is often dictated by its MSP's security practices, regardless of the organization's own internal defenses. Know that standard attack vectors against MSPs include compromising vendor software updates, exploiting vulnerabilities in RMM tools like Kaseya VSA, and credential stuffing against remote access solutions such as VPNs and Citrix. You should understand that contractual Service Level Agreements (SLAs) often lack specific, enforceable security requirements, creating a potential governance gap. Know that threat actors actively research MSPs and their client lists to identify high-value targets, making any MSP with lucrative clients a potential victim. It is essential to know that detection is complex because malicious activity can mimic legitimate administrative actions performed daily by the MSP's technicians. Furthermore, know that recovery from such an attack is a multi-party crisis requiring coordinated incident response between the MSP and all affected clients, often overwhelming resources.
Common questions
A common question is whether small businesses are at risk if they use a large, reputable MSP, and the answer is yes, as the MSP's size can make it a more attractive target. Clients frequently ask how they can monitor or audit the security practices of their MSP, which involves demanding transparency reports, third-party audit results, and clear security policies. Many wonder if they should avoid using an MSP altogether, but the more practical approach is to implement a shared responsibility model and enhanced due diligence during vendor selection. A recurring question concerns liability for breaches originating at the MSP, which is a complex legal issue dependent on contract language, regulatory standards, and applicable laws. Organizations often ask what immediate steps to take if their MSP announces a breach, which includes isolating their network from the MSP's management tools, forcing credential resets, and initiating independent monitoring. Another frequent inquiry is about the role of cyber insurance, and whether policies cover incidents stemming from a compromised third-party provider, which requires careful policy review.
Pros and cons
A significant con for defenders is the extreme difficulty of detection, as malicious activity is cloaked within legitimate administrative traffic and trusted tooling. Another pro for attackers is the rich access gained, often at the highest privilege levels (domain admin, root), which are necessary for MSPs to function but catastrophic if abused. A major con for client organizations is the loss of direct control and visibility into their own security perimeter, creating a dangerous dependency. The model also presents a pro for ransomware gangs in terms of leverage, as they can pressure the MSP to coordinate payments from multiple clients to restore services quickly. A final con is the complex and costly attribution and remediation process, which often stalls because the MSP must lead the response while itself being a victim of the attack.
Who it suits
This attack strategy suits nation-state espionage groups seeking broad, stealthy access to the intellectual property and data of multiple organizations within a specific sector or region. It particularly suits sophisticated criminal ransomware syndicates that prioritize scale and volume, aiming to extort many organizations from a single point of compromise. The tactic suits attackers who have the patience for reconnaissance, as successfully compromising an MSP often requires detailed research into its software stack, employees, and client base. It does not suit low-skilled or opportunistic attackers, as breaching an MSP typically requires more advanced techniques than targeting a single, less-secure end-user. Ultimately, this campaign method suits any threat actor whose goal is to maximize impact while minimizing the number of direct attacks they must launch and maintain.
Latest Attacks On Managed Service Providers news
Latest reporting

NetScaler CVE-2026-88771 and CVE-2026-88772 Exploited
Two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in zero-day attacks to deploy webshells

Cloudflare Containers residual data
Cloudflare fixed a cross-tenant data leakage flaw in its Containers service after a researcher demonstrated that residual data from other customers...

Check Point Zero-Day Exploited in Targeted July Attacks
Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in targeted attacks in July.

Microsoft Warns of Passkey Phishing Cloud Attacks
Microsoft details two campaigns: one blasting CEO-impersonation invoice scams and another using passkey-themed social engineering to hijack Microsoft...

GitGuardian Honeytoken Deploys Decoys to Catch Credential
GitGuardian's Honeytoken service uses decoy credentials deployed via MDM to detect credential harvesting in real time, alerting when stolen keys are

Google Warns AI Gives Lesser Attackers Nation-State
Google's Threat Intelligence Group reports that both criminal and state-backed hackers are using AI to automate attacks, enabling smaller groups to...