Ascension

Dec 2024 · Graded Attested · Healthcare and Life Sciences · Beyond the filings

Incident summary

AscensionDec 2024
$1.3B
Total reported cost
Total incident cost
Ascension stated that an employee at one of its facilities accidentally downloaded a malicious file they believed was legitimate, which the company characterised as an honest mistake. Security reporting also linked the intrusion to the suspected exploitation of CVE-2024-1709, a vulnerability in ConnectWise's ScreenConnect remote-access software. The combination highlights how a single user action and unpatched third-party software can open the door to a major ransomware incident.
Losses on the record
See the full accounting
Total incident cost · realized$1.3B · A
Shown individually, never summed across measures.
Attested: a published report credits an identifiable source for this figure.
Healthcare and Life Sciences
Company PR statements
Initial attack type phishing or social engineering confirmed · Impact ransomware confirmed
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
undated$1.3BAAttestedCompany PR statements ↗

About this record

This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete Beyond the Filings ledger ← Back to the index