2021 CompuCom — DarkSide ransomware; MSP-wide encryption; ~$20–28M remediation costs (Feb–Mar)
Data compromised
Internal corporate and service-management data; potential operational artifacts—customer-system impact framed as service disruption more than host encryption
Technical writeup
U.S. managed services provider CompuCom sustained a DarkSide ransomware intrusion disclosed in late February–early March 2021, with BleepingComputer, SecurityWeek, CRN, and MSSP Alert describing Cobalt Strike-assisted credential access followed by enterprise encryption that knocked out internal and customer-facing MSP portals for weeks. Parent filings and channel reporting aggregated tens of millions of USD in expected incident and lost-revenue costs. CompuCom emphasized it found no evidence customer endpoints were directly encrypted, while noting DarkSide’s typical data-exfiltration playbook left residual uncertainty until investigations matured.
Root cause
Human-operated ransomware deployment on MSP core IT (attributed in press to DarkSide tooling/TTPs)