Ascension
Dec 2024 · Graded Attested · Healthcare and Life Sciences · Beyond the filings
Incident summary
AscensionDec 2024
$1.3B
Total reported cost
Total incident cost
Ascension stated that an employee at one of its facilities accidentally downloaded a malicious file they believed was legitimate, which the company characterised as an honest mistake. Security reporting also linked the intrusion to the suspected exploitation of CVE-2024-1709, a vulnerability in ConnectWise's ScreenConnect remote-access software. The combination highlights how a single user action and unpatched third-party software can open the door to a major ransomware incident.
Losses on the record
See the full accounting
Total incident cost · realized$1.3B · A
Source:
Shown individually, never summed across measures.
Attested: a published report credits an identifiable source for this figure.
Company PR statements
Initial attack type phishing or social engineering confirmed · Impact ransomware confirmed
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.