{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:18.789Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou","title":"Ascension ransomware attack began when an employee downloaded a malicious file","date":"2024-05-08","date_precision":"day","year":2024,"victim_org":"Ascension","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5600000,"threat_actor":"Black Basta (reported)","summary":"Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.","how_it_worked":"A staff member downloaded a file to a work computer in the belief that it was legitimate, which is the form of compromise that has largely replaced the classic attachment: the user is looking for something, a document, an update, a utility, and takes delivery of malware from what appears to be an ordinary source. That single endpoint gave the operators their foothold in a health system spanning 140 hospitals, where the pressure to keep clinical systems continuously available works against aggressive segmentation. The attackers reached and exfiltrated data from seven servers before deploying encryption, forcing weeks of downtime procedures across the network.","lessons":"Application allowlisting and blocking user-initiated downloads of executables on clinical endpoints, combined with segmentation, are what keep one mistaken download from stopping 140 hospitals.","confidence":"Confirmed","sources":[{"title":"Ascension hacked after employee downloaded malicious file","url":"https://www.bleepingcomputer.com/news/security/ascension-hacked-after-employee-downloaded-malicious-file/","publisher":"BleepingComputer"},{"title":"Ascension cyberattack exposes data from 5.6 million people","url":"https://www.healthcaredive.com/news/ascension-cyberattack-data-breach-5-6-million/736167/","publisher":"Healthcare Dive"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou"}]}