On 29 June 2026, following a third-party security intelligence definition update, a component of the Datto RMM agent was incorrectly identified as malicious on certain devices.
As a result, affected Datto RMM agents stopped functioning as expected, causing affected devices to appear offline within the Datto RMM portal.
Kaseya promptly investigated the issue, engaged with the third-party provider, and worked collaboratively to resolve the misclassification. Updated security intelligence definitions were subsequently released, resulting in misclassification no longer occurring on devices already updated with the new definitions.
Based on the investigation, this incident was determined to be the result of a false positive detection and was not caused by actual malware or ransomware activity.
Affected customers may have experienced:
Manual intervention was required on affected devices to restore agent functionality.
The incident was caused by a false positive security detection generated by a third-party security product, which incorrectly identified legitimate Datto RMM software activity as malicious.
While we wait for the technical RCA from the third-party provider for a formal root cause for the false positive detection, the issue was resolved through the updated security intelligence definitions that corrected the classification.
Based on the investigation, the Datto RMM software involved in this event functioned as designed and was not determined to be the source of the false positive detection.
The review also identified opportunities to strengthen pre-release validation and incident response processes to better detect and respond to similar third-party security classification issues.
This incident highlighted the importance of close coordination with security vendors and the need for continued validation of software releases against evolving security detection mechanisms.
The review also reinforced the importance of rapid escalation, vendor collaboration, and timely customer communications when addressing false positive detections.
To reduce the likelihood and impact of similar incidents in the future, Kaseya is implementing the following improvements:
We are strengthening collaboration with security vendors to improve pre-release validation and reduce the likelihood of false positive detections affecting customers.
We are expanding release validation procedures to include additional security compatibility testing across representative customer environments.
We are improving monitoring and alerting capabilities to more quickly identify and assess abnormal security detections involving Datto RMM software.
We are updating incident response processes to accelerate investigation, vendor engagement, and customer communications when similar events occur.