Executive Summary
In February 2024, Ascension, one of the largest healthcare organizations in the United States, suffered a massive ransomware attack linked to longstanding encryption flaws in Microsoft’s default configurations. Attackers infiltrated Ascension’s network via a phishing email opened by a contractor on a company laptop using default Microsoft Edge and Bing settings. Exploiting weak encryption (RC4) and leveraging the Kerberoasting technique on Microsoft Active Directory, the ransomware group rapidly gained administrative privileges and deployed malware across the organization’s systems. This breach compromised sensitive data belonging to over 5.6 million patients, including personal, medical, payment, insurance, and government identification records, and severely disrupted business operations.
Why This Matters Now
This incident highlights the ongoing risk posed by outdated encryption standards and weak default security postures in widely used enterprise software, especially in critical infrastructure sectors like healthcare. Regulatory scrutiny is intensifying, as persistent vulnerabilities continue to be exploited for ransomware and data theft.
Attack Path Analysis
The attack began when a contractor's laptop was compromised through a phishing link accessed in a web browser, resulting in initial malware infection. Attackers then used Kerberoasting to escalate privileges and gain access to privileged accounts in Active Directory, exploiting weak encryption (RC4) and insufficient password controls. With administrative access, the adversaries moved laterally throughout the organization's internal network, expanding their foothold. They established command and control to coordinate further activities and potentially maintain persistence. The attackers exfiltrated sensitive patient, medical, and payment data from the environment. Ultimately, ransomware was deployed across thousands of endpoints, causing business disruption and large-scale impact.
Kill Chain Progression
Initial Compromise
Description
A contractor clicked a phishing link in the default web browser, resulting in malware infection of their device.
Related CVEs
CVE-2024-XXXX
CVSS 8.8A vulnerability in Microsoft Active Directory allows attackers to perform Kerberoasting attacks by exploiting the continued support for the insecure RC4 encryption algorithm, potentially leading to unauthorized access to privileged accounts.
Affected Products:
Microsoft Active Directory – All versions supporting RC4 encryption
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
User Execution: Malicious Link
Valid Accounts
Steal or Forge Kerberos Tickets: Kerberoasting
Exploitation for Privilege Escalation
Data Encrypted for Impact
Brute Force: Password Spraying
OS Credential Dumping: DCSync
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Authentication
Control ID: 8.3.4
NYDFS 23 NYCRR 500 – Information Security Program
Control ID: 500.03
DORA – ICT Risk Management Requirements
Control ID: Article 10
CISA ZTMM 2.0 – Enforce Strong Authentication and Credential Management
Control ID: Identity: 1.3
NIS2 Directive – Security of Network and Information Systems: Supply Chain Security
Control ID: Article 21(2)(d)
HIPAA Security Rule – Encryption and Decryption of ePHI
Control ID: 45 CFR §164.312(a)(2)(iv)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Ascension hospital ransomware attack demonstrates critical vulnerability to Kerberoasting and RC4 exploitation, compromising 5.6 million patient records and medical infrastructure.
Government Administration
Microsoft's default RC4 configurations expose federal agencies to ransomware via Kerberoasting attacks, contradicting CISA warnings and compromising critical infrastructure security.
Financial Services
Banking institutions using Microsoft Active Directory face elevated ransomware risk through RC4 vulnerabilities, threatening payment systems and customer financial data protection.
Information Technology/IT
IT organizations managing Microsoft environments are particularly vulnerable to lateral movement and privilege escalation through obsolete RC4 encryption and inadequate default configurations.
Sources
- Wyden calls on FTC to investigate Microsoft for ‘gross cybersecurity negligence’ in protecting critical infrastructurehttps://cyberscoop.com/ron-wyden-ftc-microsoft-default-security-flaws-rc4-kerberoasting-ascension-ransomware/Verified
- A cyberattack forces a big US health system to divert ambulances and take records offlinehttps://apnews.com/article/728ab2a0e5afaf7c344e46a5ce5ca42cVerified
- Ascension: 'Systems Are Being Restored' After Cyberattackhttps://www.crn.com/news/security/2024/ascension-systems-are-being-restored-after-cyberattackVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, strong encryption enforcement, east-west traffic controls, and rigorous egress policy could have limited the attacker's propagation, detected abnormal behaviors, and prevented data exfiltration or mass ransomware impact. Network and workload microsegmentation, encryption modernization, and real-time anomaly detection are critical to containing such threats.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious user activity or compromised endpoint access is detected quickly.
Control: Encrypted Traffic (HPE)
Mitigation: Compromise via obsolete or insecure encryption protocols is prevented.
Control: Zero Trust Segmentation
Mitigation: Movement between network segments and workloads is blocked unless explicitly permitted.
Control: Cloud Firewall (ACF)
Mitigation: Outbound connections to unapproved domains or IPs are detected or blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts are blocked and alerted.
Automated propagation of ransomware is halted between workloads.
Impact at a Glance
Affected Business Functions
- Emergency Services
- Patient Records Management
- Diagnostic Testing
- Pharmacy Services
Estimated downtime: 30 days
Estimated loss: $1,800,000,000
Unauthorized access to personal and sensitive health information of approximately 5.6 million patients, including medical records, payment information, and government identification numbers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce modern encryption algorithms across all authentication and internal network traffic to eliminate legacy protocol risks like RC4.
- • Implement Zero Trust Segmentation to restrict lateral movement and confine high-privileged accounts to their intended network zones.
- • Deploy advanced egress controls and anomaly detection to spot unauthorized outbound traffic or data exfiltration attempts in real time.
- • Continuously review and update privileged access policies and password requirements for administrative accounts, ensuring alignment with cloud security best practices.
- • Centralize visibility and incident monitoring across multicloud and hybrid environments to rapidly detect and contain malicious activity before impact.



