{
  "id": "case-ascension-black-basta",
  "slug": "ascension-health-black-basta-ransomware",
  "title": "Ascension Health Network Black Basta Ransomware Outage",
  "summary": "Severe ransomware incident paralyzing Ascension Health, one of the nation largest nonprofit Catholic hospital systems across 140 facilities in 14 states, forcing clinical staff to paper medical charts, diverting emergency trauma patients, and triggering CISA joint advisories on Russian-linked Black Basta operations.",
  "case_number": "HHS-OCR-2024-ASC",
  "court": "U.S. Department of Health and Human Services OCR Enforcement",
  "district": "National",
  "country": "United States",
  "opened_at": "2024-05-08",
  "status": "investigation",
  "victim_sector": "Healthcare & Hospitals",
  "victim_country": "United States",
  "loss_amount_usd": 1300000000,
  "loss_amount_note": "Estimated operational disruption, diverted surgical revenue, and remediation expenses.",
  "first_seen_at": "2024-05-08T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "unattributed-cybercrime",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Black Basta deployed ransomware across Windows domain controllers and VMware ESXi hypervisors, appending the .basta extension and deleting Volume Shadow Copies.",
      "evidence_locator": "CISA Advisory AA24-131A: StopRansomware Black Basta",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-131A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Initial entry was traced to spearphishing and malicious advertising delivering Qakbot or Cobalt Strike loaders onto hospital administrative endpoints.",
      "evidence_locator": "Health-ISAC Alert on Black Basta Healthcare Attacks",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Health-ISAC Advisory",
      "source_url": "https://h-isac.org",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-05-08",
      "description": "Ascension detects unusual activity and severs network access across electronic health record systems."
    },
    {
      "event_type": "advisory",
      "event_date": "2024-05-10",
      "description": "CISA, FBI, and HHS issue joint alert AA24-131A detailing Black Basta targeting of healthcare organizations."
    },
    {
      "event_type": "restoration",
      "event_date": "2024-06-14",
      "description": "Ascension completes nationwide electronic medical record access restoration across all 140 hospitals."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Accidental employee download of malicious payload via search engine malvertising and malicious attachments, delivering initial Qakbot and Cobalt Strike loaders.",
    "blast_radius": "Paralyzed electronic health record access across 140 hospitals in 14 states, forcing clinical staff onto paper charts, diverting ambulances, and triggering emergency CISA/FBI/HHS healthcare advisories.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Search Malvertising & Phishing Delivery",
        "description": "Hospital administrative workstation compromised through malicious search advertising delivering a trojanized utility installer.",
        "technical_artifacts": [
          "Malicious installer payload",
          "Cobalt Strike beacon"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Lateral Movement",
        "title": "Active Directory & Hypervisor Enumeration",
        "description": "Adversaries extracted domain administrative credentials and mapped VMware ESXi hypervisor clusters hosting clinical electronic medical record databases.",
        "technical_artifacts": [
          "Mimikatz credential dump",
          "ESXi CLI enumeration"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Defense Evasion",
        "title": "EDR Agent Disablement",
        "description": "Threat actors deployed custom batch scripts and exploit drivers to terminate endpoint security services across domain servers.",
        "technical_artifacts": [
          "EDR kill scripts",
          "Vulnerable driver execution"
        ],
        "mitre_technique_id": "T1562.001"
      },
      {
        "phase": "Encryption Detonation",
        "title": "Black Basta Payload Detonation",
        "description": "Ransomware binary executed across virtual machine hypervisors and storage area networks, appending .basta extensions and encrypting virtual disks.",
        "technical_artifacts": [
          "Black Basta payload",
          ".basta encrypted files"
        ],
        "mitre_technique_id": "T1486"
      },
      {
        "phase": "Clinical Impact",
        "title": "Nationwide Emergency Patient Diversion",
        "description": "Ascension severed electronic health records, diagnostic imaging portals, and pharmacy dispensing systems, forcing doctors to manual paper workflows.",
        "technical_artifacts": [
          "EHR network isolation",
          "Diverted emergency services"
        ],
        "mitre_technique_id": "T1489"
      }
    ],
    "defensive_takeaways": [
      "Maintain isolated, verified offline backups of electronic health records and picture archiving systems.",
      "Harden VMware ESXi hypervisors by restricting administrative access to dedicated management subnets with MFA.",
      "Establish tested manual paper downtime procedures for clinical hospital staff during digital outages.",
      "Deploy DNS-layer filtering to block malicious advertising and newly registered lure domains."
    ]
  }
}