Ransomware

Dish Network Ransomware Attack (Black Basta, Multi-Day Outage, 296K Employee Records)

πŸ“… 2023-02-23 🦠 Black Basta ransomware
Primary Source β†—

Incident Details

On February 23, 2023, Dish Network β€” a major US satellite TV provider β€” suffered a ransomware attack (attributed to Black Basta) that took down its internal systems, customer service centers, and multiple customer-facing applications for several days. Dish Network, Sling TV, Boost Mobile, and other subsidiary services experienced widespread disruptions including inability for customers to pay bills online or reach customer support. Dish’s websites and apps went offline. Dish disclosed the ransomware attack in an SEC 8-K filing on February 28, 2023. A subsequent data breach notification filed with the Maine Attorney General revealed that approximately 296,851 individuals β€” primarily current and former employees β€” had personal data stolen, including driver’s license numbers. Dish reportedly paid the ransom to obtain a decryptor. The attack and poor incident communication caused significant customer anger and regulatory scrutiny.

Technical Details

Initial Attack Vector
Attackers used compromised VPN credentials to access Dish Network's Windows Active Directory domain, then moved laterally and deployed ransomware across Dish's IT infrastructure
Malware Family
Black Basta ransomware

Timeline

  1. 2023-02-23 Breach occurred
  2. 2023-02-27 Publicly disclosed
  3. 2023-05-22 Customers notified