UPDATED 20:01 EDT / JUNE 13 2024

SECURITY

Black Basta ransomware group suspected in Ascension data theft incident

U.S. healthcare provider Ascension has provided more details of its “cyber security event” last month, admitting that data was stolen, with some reports also suggesting that the Black Basta ransomware gang was behind the attack.

One of the largest nonprofit and Catholic health systems in the U.S. and also the second-largest operator of hospitals in the U.S. as of 2019, Ascension first disclosed that it had suffered a security issue on May 5. At the time, Ascension said the attack had disrupted clinical operations and was advising business partners to suspend their connections to the Ascension environment temporarily.

In a statement on Wednesday, Ascension said it had made progress in its investigation and recovery and it now has evidence that the attackers were able to take files from a small number of file services used by associates for daily and routine takes. Some of those servers were found to contain protected health information and personally identifiable information for certain individuals.

Ascension also disclosed that it had found the way the attack had gained access to its systems: An individual “working in one of our facilities accidentally downloaded a malicious file that they thought was legitimate.” It said it has “no reason to believe this was anything but an honest mistake.”

The nonprofit added that, as of now, it doesn’t know exactly what data was potentially affected and for which patients. The investigation is ongoing.

Though Ascension didn’t disclose the form of attack, CNN, referencing four sources, reported last month that it was a Black Basta attack. Also indicating that it was likely Black Basta was a warning from the Health Information Sharing and Analysis Center on May 10 — two days after the Ascension attack — warning that Black Basta was actively targeting healthcare organizations.

A report released yesterday from the Threat Hunter Team at Symantec detailed how Black Basta is suspected of using a patched Windows flaw in recent cyberattacks. Although the report doesn’t name Ascension, that Black Basta, which first appeared in 2022, has been found to be highly active recently also gives credence to the idea that Ascension may have been targeted by the group.

Discussing the attack vector, Max Gannon, cyber intelligence team manager at phishing protection solutions company Cofense Inc., told SiliconANGLE that “unfortunately, it really only takes one person making an honest mistake.”

“This is why training is so critical. Basic cyber literacy is becoming more common, but truly instilling a sense of suspicion when it comes to online interactions and activities takes time and a serious investment on the company’s part,” Gannon added. “Ascension has responded well to the breach, keeping relevant parties updated and offering monitoring even for parties that were likely unaffected.”

Photo: Ascension

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.