Ascension Health Network Black Basta Ransomware Outage
Key Facts
- Legal Status: INVESTIGATION in U.S. Department of Health and Human Services OCR Enforcement.
- Primary Target Sector: Healthcare & Hospitals.
- Documented Financial Loss: $1.3 billion.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Accidental employee download of malicious payload via search engine malvertising and malicious attachments, delivering initial Qakbot and Cobalt Strike loaders.
Operational & Financial Fallout
Paralyzed electronic health record access across 140 hospitals in 14 states, forcing clinical staff onto paper charts, diverting ambulances, and triggering emergency CISA/FBI/HHS healthcare advisories.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Accidental employee download of malicious payload via search engine malvertising and malicious attachments, delivering initial Qakbot and Cobalt Strike loaders.
Adversary Kill Chain Flow
5 Documented PhasesHospital administrative workstation compromised through malicious search advertising delivering a trojanized utility installer.
Adversaries extracted domain administrative credentials and mapped VMware ESXi hypervisor clusters hosting clinical electronic medical record databases.
Threat actors deployed custom batch scripts and exploit drivers to terminate endpoint security services across domain servers.
Ransomware binary executed across virtual machine hypervisors and storage area networks, appending .basta extensions and encrypting virtual disks.
Ascension severed electronic health records, diagnostic imaging portals, and pharmacy dispensing systems, forcing doctors to manual paper workflows.
Paralyzed electronic health record access across 140 hospitals in 14 states, forcing clinical staff onto paper charts, diverting ambulances, and triggering emergency CISA/FBI/HHS healthcare advisories.
Procedural & Incident Timeline
Ascension detects unusual activity and severs network access across electronic health record systems.
CISA, FBI, and HHS issue joint alert AA24-131A detailing Black Basta targeting of healthcare organizations.
Ascension completes nationwide electronic medical record access restoration across all 140 hospitals.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1486 | Data Encrypted for Impact Impact | "Black Basta deployed ransomware across Windows domain controllers and VMware ESXi hypervisors, appending the .basta extension and deleting Volume Shadow Copies." | CISA Advisory AA24-131A: StopRansomware Black Basta | reviewed |
| T1566.001 | Spearphishing Attachment Initial Access | "Initial entry was traced to spearphishing and malicious advertising delivering Qakbot or Cobalt Strike loaders onto hospital administrative endpoints." | Health-ISAC Alert on Black Basta Healthcare Attacks | reviewed |