Ransomware

Dish Network / EchoStar BlackBasta Ransomware β€” Employee Data, 300K+ Affected

πŸ“… 2023-02-23 🏒 Dish Network / EchoStar internal systems 🦠 Black Basta ransomware
Primary Source β†—

Incident Details

On 23 February 2023, Dish Network and its parent EchoStar suffered a Black Basta ransomware attack that caused a several-day outage affecting Dish Network’s websites, call centers, and internal systems. Dish.com, Sling TV, and Dish’s customer service systems were all disrupted. Dish Network is a US satellite broadcasting company serving approximately 10 million subscribers. The attack caused an extended outage of approximately one week for customer-facing services. The company was unable to confirm whether customer personal data was stolen. In subsequent SEC 8-K filings, Dish disclosed that certain data had been extracted and that it was paying cybersecurity firms and legal counsel to investigate. Dish notified the Montana attorney general in June 2023 that approximately 296,851 Montana residents (and an undetermined total number of individuals across all states) had their data stolen including names, Social Security numbers, and other personal data β€” specifically of current and former employees. Black Basta claimed responsibility. Dish did not make a public statement confirming the ransom payment, though subsequent reports suggested Dish did pay to prevent data publication. The attack significantly impacted Dish’s business operations and contributed to the company’s financial difficulties.

Technical Details

Initial Attack Vector
Black Basta ransomware group attacked Dish Network's internal network; specific initial access vector not publicly disclosed; the attack encrypted internal systems and exfiltrated data
Vendor / Product
Dish Network / EchoStar internal systems
Malware Family
Black Basta ransomware

Timeline

  1. 2023-02-23 Breach occurred
  2. 2023-03-01 Publicly disclosed
  3. 2023-06-01 Customers notified