01Summary
On May 8, 2024, Black Basta deployed ransomware across Ascension's network, forcing the healthcare giant to divert emergency ambulances, postpone non-emergency procedures, and revert to paper-based patient records. The attack affected 140 hospitals and 40 senior care facilities across 19 states. Ascension confirmed that patient data was exfiltrated before encryption, adding extortion pressure. The FBI and CISA confirmed Black Basta as the perpetrators. The attack caused significant patient safety risks due to delayed care and medication administration challenges.
02Background
Ascension is one of the largest non-profit healthcare systems in the United States, operating 140 hospitals across 19 states. Healthcare ransomware attacks pose unique patient safety risks beyond financial damage.
03Key revelations
- 01Healthcare ransomware attacks directly endanger patient safety.
- 02Black Basta was able to cripple one of the largest U.S. hospital systems.
04Technical analysis
Black Basta gained initial access likely through compromised credentials or spear-phishing. The attackers performed extensive network reconnaissance before deploying ransomware across critical healthcare systems including electronic health records (EHR), medication administration, and patient scheduling platforms.
- Attack vector
- Compromised credentials or spear-phishing
- Attack method
- Ransomware with data exfiltration
- Initial access
- Compromised credentials (likely)
- Lateral movement
- Network pivoting and credential abuse
- Exfiltration
- Bulk data extraction before encryption
- Tool / malware
- Black Basta Ransomware
- Malware family
- Black Basta
- Malware type
- Ransomware
05Threat actor
Black Basta is a highly active Ransomware-as-a-Service (RaaS) group known for targeting healthcare, government, and critical infrastructure organizations with double extortion tactics.
Aliases
- Black Basta Ransomware Group
Attribution sources
- FBI
- CISA
- Ascension statements
- BleepingComputer
06Victims and impact
Countries affected
- United States
07Data exposed
Data types
- Patient PII
- Medical records
- Protected Health Information (PHI)
08Financial damage
Loss of revenue during extended downtime; patient safety risks; regulatory fines under HIPAA.
09Timeline
- 2024-05-08Ransomware attack begins; ambulances diverted.
- 2024-05-09Ascension publicly discloses the incident.
10Reaction and fallout
Public reaction
Widespread concern over patient safety risks from healthcare ransomware attacks.
Political impact
Increased congressional pressure for mandatory cybersecurity standards in healthcare.
11Legal
Multiple class-action lawsuits; HHS/OCR investigation under HIPAA.
Civil lawsuits
- Class-action lawsuits related to patient data exposure and care delays
12Aftermath
Policy changes
- Calls for mandatory minimum cybersecurity standards for hospitals.
13Significance and legacy
Significance
One of the most disruptive healthcare ransomware attacks, affecting 140 hospitals across 19 states.
Legacy
Redefined the threat model for healthcare cybersecurity, emphasizing patient safety impact over financial loss.
14Disclosure and media
- Authentication
- Ascension confirmation and FBI/CISA attribution
Publishing organisations
- BleepingComputer
- Associated Press
- FBI/CISA joint advisory
16Field notes
- 01Ascension operates 140 hospitals and 40 senior care facilities across 19 U.S. states.
17Resolution
Ascension gradually restored systems over several weeks; patient care returned to normal operations.
18Sources
Official documents
- Ascension incident statements
- FBI/CISA advisory on Black Basta
References
- [1]BleepingComputer: Ascension ransomware coverage
- [2]FBI/CISA joint advisory









