DISH Network confirms ransomware attack behind multi-day outage
- Organization
- DISH Network Corporation
- Exploit
- Ransomware
- Industry
- Telecommunications
DISH Network Corporation lost much of its customer facing infrastructure on February 23, 2023. Its website, the Dish Anywhere app, internal communications, customer call centers and services at subsidiaries including Boost Mobile were disrupted for several days, leaving subscribers unable to reach support or manage their accounts.
The company initially described the problem as an internal outage. In a Form 8-K filed with the U.S. Securities and Exchange Commission at the end of February, DISH confirmed the outage was caused by a cybersecurity incident, said it had notified law enforcement and acknowledged that data had been extracted from its IT systems, potentially including personal information.
Reporting at the time linked the intrusion to the Black Basta ransomware operation, with sources suggesting Boost Mobile was compromised before the corporate network. DISH did not attribute the attack publicly and no group posted it to a leak site.
In May 2023 the company filed breach notifications reporting that 296,851 people were affected, almost all of them employees, former employees and family members. DISH said customer databases were not accessed. Stolen information included driver's license numbers, and affected individuals were offered two years of credit monitoring.
DISH also told those individuals it had received confirmation that the extracted data was deleted, wording that several outlets read as an indication a ransom had been paid. The company did not comment on any payment.
Sources
- TechCrunch, Dish confirms ransomware attack allowed hackers to steal personal data
- BleepingComputer, Dish Network confirms ransomware attack behind multi-day outage
- SecurityWeek, Dish Ransomware Attack Impacted Nearly 300,000 People
- The Record (Recorded Future News), Nearly 300,000 people affected by data breach in DISH ransomware attack