← CompuCom

2021 CompuCom — DarkSide ransomware; MSP-wide encryption; ~$20–28M remediation costs (Feb–Mar)

2021 Unknown records affected Share on X

Data compromised

Internal corporate and service-management data; potential operational artifacts—customer-system impact framed as service disruption more than host encryption

Technical writeup

U.S. managed services provider CompuCom sustained a DarkSide ransomware intrusion disclosed in late February–early March 2021, with BleepingComputer, SecurityWeek, CRN, and MSSP Alert describing Cobalt Strike-assisted credential access followed by enterprise encryption that knocked out internal and customer-facing MSP portals for weeks. Parent filings and channel reporting aggregated tens of millions of USD in expected incident and lost-revenue costs. CompuCom emphasized it found no evidence customer endpoints were directly encrypted, while noting DarkSide’s typical data-exfiltration playbook left residual uncertainty until investigations matured.

Root cause

Human-operated ransomware deployment on MSP core IT (attributed in press to DarkSide tooling/TTPs)

References