Skip to content
NetarxNetarx
Spear Phishing (Email)No AI reportedConfirmed

Ascension ransomware attack began when an employee downloaded a malicious file

Ascension · Healthcare · United States · May 8, 2024

Business impact
$1,300,000,000
Lost revenue, earnings impact, remediation cost, a settlement or damages sought. Not money stolen.
Ascension never published a discrete attack cost. The roughly $1.3 billion figure is the deterioration in its FY2024 recurring-operations result between the ten-month report (a $79 million loss) and the full year (a $1.4 billion loss), a period dominated by the attack's revenue-cycle disruption and remediation costs. It is a business-impact estimate, not money paid to attackers, and is never added into summed totals.
People or records affected
5,600,000
5.6M as reported

What happened

Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.

How the deception worked

A staff member downloaded a file to a work computer in the belief that it was legitimate, which is the form of compromise that has largely replaced the classic attachment: the user is looking for something, a document, an update, a utility, and takes delivery of malware from what appears to be an ordinary source. That single endpoint gave the operators their foothold in a health system spanning 140 hospitals, where the pressure to keep clinical systems continuously available works against aggressive segmentation. The attackers reached and exfiltrated data from seven servers before deploying encryption, forcing weeks of downtime procedures across the network.

The control that would have caught it· our reading, not a claim from the sources

Application allowlisting and blocking user-initiated downloads of executables on clinical endpoints, combined with segmentation, are what keep one mistaken download from stopping 140 hospitals.

Sources (3)

  1. Ascension hacked after employee downloaded malicious file
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. Ascension cyberattack exposes data from 5.6 million people
    Healthcare Dive·healthcaredive.comOpen ↗
  3. Ascension's spring ransomware attack stunts FY24 financial recovery
    Fierce Healthcare·fiercehealthcare.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.