Security News > 2024 > May > CISA: Black Basta ransomware breached over 500 orgs worldwide

CISA and the FBI said today that Black Basta ransomware affiliates breached over 500 organizations between April 2022 and May 2024.
"Black Basta affiliates have targeted over 500 private industry and critical infrastructure entities, including healthcare organizations, in North America, Europe, and Australia," CISA said.
"The level of sophistication by its proficient ransomware operators, and reluctance to recruit or advertise on Dark Web forums, supports why many suspect the nascent Black Basta may even be a rebrand of the Russian-speaking RaaS threat group Conti, or also linked to other Russian-speaking cyber threat groups."
Defenders should keep operating systems, software, and firmware up-to-date, require phishing-resistant Multi-Factor Authentication for as many services as possible, and train users to recognize and report phishing attempts to mitigate Black Basta ransomware attack risks.
While the federal agencies didn't share what prompted today's advisory, Black Basta was linked this week to a suspected ransomware attack that hit the systems of healthcare giant Ascension, forcing the U.S. healthcare network to redirect ambulances to unaffected facilities.
On Friday, Health-ISAC also issued a threat bulletin warning that the Black Basta ransomware gang "Has recently accelerated attacks against the healthcare sector."
News URL
Related news
- CISA and FBI: Ghost ransomware breached orgs in 70 countries (source)
- Black Basta ransomware gang's internal chat logs leak online (source)
- Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal Conflicts (source)
- Southern Water says Black Basta ransomware attack cost £4.5M in expenses (source)
- Ransomware criminals love CISA's KEV list – and that's a bug, not a feature (source)
- Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates (source)
- Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware (source)
- CISA: Medusa ransomware hit over 300 critical infrastructure orgs (source)
- Medusa Ransomware Strikes 300+ Targets: FBI & CISA Urge Immediate Action to #StopRansomware (source)