EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/2024-ascension-healthcare-ransomware
095/430

File EL-0336CriticalResolvedRansomware Attack / Ransomware / Healthcare Disruption

Ascension Healthcare Ransomware Attack

Also filed as Ascension Black Basta Attack · Ascension Hospital System Hack

The Black Basta ransomware gang attacked Ascension Healthcare, one of the largest hospital systems in the United States, causing massive operational disruptions across 140 hospitals and 40 senior care facilities.

  • #ransomware
  • #healthcare
  • #hospital
  • #black-basta
  • #emergency-services-disruption
Notoriety9/10
Event
8 May 2024
Disclosed
9 May 2024
Target
Ascension Healthcare
Actor
Black Basta
Status
Resolved

01Summary

On May 8, 2024, Black Basta deployed ransomware across Ascension's network, forcing the healthcare giant to divert emergency ambulances, postpone non-emergency procedures, and revert to paper-based patient records. The attack affected 140 hospitals and 40 senior care facilities across 19 states. Ascension confirmed that patient data was exfiltrated before encryption, adding extortion pressure. The FBI and CISA confirmed Black Basta as the perpetrators. The attack caused significant patient safety risks due to delayed care and medication administration challenges.

02Background

Ascension is one of the largest non-profit healthcare systems in the United States, operating 140 hospitals across 19 states. Healthcare ransomware attacks pose unique patient safety risks beyond financial damage.

03Key revelations

  1. 01Healthcare ransomware attacks directly endanger patient safety.
  2. 02Black Basta was able to cripple one of the largest U.S. hospital systems.

04Technical analysis

Black Basta gained initial access likely through compromised credentials or spear-phishing. The attackers performed extensive network reconnaissance before deploying ransomware across critical healthcare systems including electronic health records (EHR), medication administration, and patient scheduling platforms.

Attack vector
Compromised credentials or spear-phishing
Attack method
Ransomware with data exfiltration
Initial access
Compromised credentials (likely)
Lateral movement
Network pivoting and credential abuse
Exfiltration
Bulk data extraction before encryption
Tool / malware
Black Basta Ransomware
Malware family
Black Basta
Malware type
Ransomware

05Threat actor

Black Basta is a highly active Ransomware-as-a-Service (RaaS) group known for targeting healthcare, government, and critical infrastructure organizations with double extortion tactics.

Aliases

  • Black Basta Ransomware Group

Attribution sources

  • FBI
  • CISA
  • Ascension statements
  • BleepingComputer

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Patient PII
  • Medical records
  • Protected Health Information (PHI)

08Financial damage

Loss of revenue during extended downtime; patient safety risks; regulatory fines under HIPAA.

09Timeline

  1. 2024-05-08Ransomware attack begins; ambulances diverted.
  2. 2024-05-09Ascension publicly discloses the incident.

10Reaction and fallout

Public reaction

Widespread concern over patient safety risks from healthcare ransomware attacks.

Political impact

Increased congressional pressure for mandatory cybersecurity standards in healthcare.

11Legal

Multiple class-action lawsuits; HHS/OCR investigation under HIPAA.

Civil lawsuits

  • Class-action lawsuits related to patient data exposure and care delays

12Aftermath

Policy changes

  • Calls for mandatory minimum cybersecurity standards for hospitals.

13Significance and legacy

Significance

One of the most disruptive healthcare ransomware attacks, affecting 140 hospitals across 19 states.

Legacy

Redefined the threat model for healthcare cybersecurity, emphasizing patient safety impact over financial loss.

14Disclosure and media

Authentication
Ascension confirmation and FBI/CISA attribution

Publishing organisations

  • BleepingComputer
  • Associated Press
  • FBI/CISA joint advisory

15Related files

Related events

16Field notes

  1. 01Ascension operates 140 hospitals and 40 senior care facilities across 19 U.S. states.

17Resolution

Ascension gradually restored systems over several weeks; patient care returned to normal operations.

18Sources

Official documents

  • Ascension incident statements
  • FBI/CISA advisory on Black Basta

References

  1. [1]BleepingComputer: Ascension ransomware coverage
  2. [2]FBI/CISA joint advisory
Fact sheetEL-0336

Dates

Event
8 May 2024
Started
8 May 2024
Discovered
8 May 2024
Disclosed
9 May 2024
Ongoing
No

Target

Organisation
Ascension Health
Type
Healthcare Organization
Sector
Healthcare
Country
United States

Actor

Name
Black Basta
Type
Ransomware Gang
Motivation
Financial gain through ransomware extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Critical
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.