Datto incident

Datto RMM - Syrah, Vidal - 15.0.1 Cagservice.exe being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint

Major Resolved View vendor source →

Datto experienced a major incident on June 29, 2026 affecting Syrah (APAC) and Vidal (US East), lasting 15d 22h. The incident has been resolved; the full update timeline is below.

Started
Jun 29, 2026, 04:02 PM UTC
Resolved
Jul 15, 2026, 02:25 PM UTC
Duration
15d 22h
Detected by Pingoru
Jun 29, 2026, 04:02 PM UTC

Affected components

Syrah (APAC)Vidal (US East)

Update timeline

  1. investigating Jun 29, 2026, 04:02 PM UTC

    We are aware of a problem where Datto RMM's 15.0.1 Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint. The Kaseya R&D Team are investigating this issue. Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/

  2. investigating Jun 29, 2026, 04:07 PM UTC

    We are continuing to investigate this issue.

  3. identified Jun 29, 2026, 07:36 PM UTC

    The issue has been identified and a fix is being implemented.

  4. monitoring Jun 29, 2026, 10:47 PM UTC

    A fix has been implemented and we are monitoring the results.

  5. resolved Jul 15, 2026, 02:25 PM UTC

    This incident has been resolved.

  6. postmortem Jul 16, 2026, 08:47 AM UTC

    ## **Summary** On 29 June 2026, following a third-party security intelligence definition update, a component of the Datto RMM agent was incorrectly identified as malicious on certain devices. As a result, affected Datto RMM agents stopped functioning as expected, causing affected devices to appear offline within the Datto RMM portal. Kaseya promptly investigated the issue, engaged with the third-party provider, and worked collaboratively to resolve the misclassification. Updated security intelligence definitions were subsequently released, resulting in misclassification no longer occurring on devices already updated with the new definitions. Based on the investigation, this incident was determined to be the result of a false positive detection and was not caused by actual malware or ransomware activity. ### **Customer Impact Assessment** Affected customers may have experienced: * Devices appearing offline within the Datto RMM portal. * Complete interruption in agent-based management activities. * Visibility and management capabilities for affected endpoints through Datto RMM were inhibited during the incident. Manual intervention was required on affected devices to restore agent functionality. ## **Root Cause** The incident was caused by a false positive security detection generated by a third-party security product, which incorrectly identified legitimate Datto RMM software activity as malicious. While we wait for the technical RCA from the third-party provider for a formal root cause for the false positive detection, the issue was resolved through the updated security intelligence definitions that corrected the classification. Based on the investigation, the Datto RMM software involved in this event functioned as designed and was not determined to be the source of the false positive detection. The review also identified opportunities to strengthen pre-release validation and incident response processes to better detect and respond to similar third-party security classification issues. ## **Incident Timeline** ## **Lessons Learned** This incident highlighted the importance of close coordination with security vendors and the need for continued validation of software releases against evolving security detection mechanisms. The review also reinforced the importance of rapid escalation, vendor collaboration, and timely customer communications when addressing false positive detections. ### **Preventative Measures** To reduce the likelihood and impact of similar incidents in the future, Kaseya is implementing the following improvements: #### **Proactive Vendor Collaboration** We are strengthening collaboration with security vendors to improve pre-release validation and reduce the likelihood of false positive detections affecting customers. #### **Enhanced Release Validation** We are expanding release validation procedures to include additional security compatibility testing across representative customer environments. #### **Enhanced Monitoring** We are improving monitoring and alerting capabilities to more quickly identify and assess abnormal security detections involving Datto RMM software. #### **Enhanced Response Procedures** We are updating incident response processes to accelerate investigation, vendor engagement, and customer communications when similar events occur.