Executive Summary
In May 2024, Ascension Health experienced a major ransomware breach, impacting over 5.6 million patient records. Attackers exploited a contractor’s click on a malicious Bing search result in Microsoft Edge, leveraging a 'Kerberoasting' attack against Microsoft Active Directory. By abusing weak and legacy RC4-encrypted Kerberos service account credentials, attackers escalated privileges and moved laterally across sensitive healthcare infrastructure, ultimately exfiltrating patient data and disrupting operations. The incident highlighted significant shortcomings in Microsoft's default security settings and communication of critical risks to enterprise customers, even after prior warnings from security experts and U.S. government officials.
The breach is emblematic of a rising trend in identity-based and ransomware attacks exploiting outdated cryptographic standards across critical infrastructure sectors, especially healthcare. Regulatory and public scrutiny on vendor responsibility, ransomware defense, and secure default configurations have intensified following this high-profile compromise.
Why This Matters Now
This incident underscores the urgent need for businesses to address known cryptographic vulnerabilities and enforce strong authentication controls. With ransomware attacks growing in frequency and sophistication, organizations must ensure that legacy protocols like RC4 are fully disabled, and vendors are held accountable for timely, clear communication and action on critical security risks.
Attack Path Analysis
Attackers gained initial access when a contractor clicked a malicious Bing search result, delivering a payload to their device. They exploited weak Kerberos service account credentials using Kerberoasting, escalating privileges after decrypting stolen hashes. With elevated access, they moved laterally through internal networks to target critical assets. Command and control was maintained to issue remote instructions and manage the intrusion. Exfiltration of sensitive healthcare data was likely conducted, potentially bypassing weak egress controls. Finally, ransomware was deployed, causing data encryption and business disruption within healthcare environments.
Kill Chain Progression
Initial Compromise
Description
A contractor clicked a malicious Bing Search result in Microsoft Edge, enabling attackers to deliver malware and establish a foothold.
Related CVEs
CVE-2020-17049
CVSS 8.1Kerberos KDC Security Feature Bypass Vulnerability
Affected Products:
Microsoft Windows Server – 2012, 2012 R2, 2016, 2019, 2022
Exploit Status:
exploited in the wildCVE-2021-42287
CVSS 7.2Windows Kerberos Elevation of Privilege Vulnerability
Affected Products:
Microsoft Windows Server – 2012, 2012 R2, 2016, 2019, 2022
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Link
Steal or Forge Kerberos Tickets: Kerberoasting
Password Policy Discovery
Brute Force: Password Cracking
Valid Accounts
Create Account: Local Account
Exploitation of Remote Services
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
HIPAA (Health Insurance Portability and Accountability Act) – Encryption and Decryption
Control ID: 164.312(a)(2)(iv)
PCI DSS 4.0 – Secure Cryptographic Key Management
Control ID: 3.5.1
CISA Zero Trust Maturity Model 2.0 – Identity and Credential Protection
Control ID: Identity Pillar: Authentication and Access Management
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: Section 500.03
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Critical exposure to ransomware attacks via Microsoft vulnerabilities, as demonstrated by Ascension Health breach compromising 5.6 million patient records through Kerberoasting techniques.
Government Administration
National security risks from Microsoft's negligent cybersecurity practices affecting critical infrastructure, requiring FTC intervention to prevent inevitable high-impact government system breaches.
Financial Services
Vulnerable to lateral movement attacks exploiting weak RC4 encryption in Active Directory environments, risking compliance violations under stringent financial regulatory frameworks.
Information Technology/IT
Enterprise systems face systematic vulnerabilities from Microsoft's monopolistic security negligence, requiring immediate zero trust segmentation and encrypted traffic controls for client protection.
Sources
- U.S. Senator accuses Microsoft of “gross cybersecurity negligence”https://www.bleepingcomputer.com/news/security/us-senator-accuses-microsoft-of-gross-cybersecurity-negligence/Verified
- Ascension confirms ransomware caused service shutdowns, ambulance diversionshttps://healthexec.com/topics/health-it/cybersecurity/ascension-confirms-ransomware-caused-service-shutdowns-ambulance-diversionsVerified
- Ascension Says Medical Information Stolen In Attack, 5.6M Affectedhttps://www.crn.com/news/security/2024/ascension-says-medical-information-stolen-in-attack-5-6m-affectedVerified
- Microsoft’s guidance to help mitigate critical threats to Active Directory Domain Services in 2025https://www.microsoft.com/en-us/windows-server/blog/2025/12/09/microsofts-guidance-to-help-mitigate-critical-threats-to-active-directory-domain-services-in-2025Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
CNSF capabilities such as Zero Trust Segmentation, East-West Traffic Security, strong encryption for data-in-transit, and egress controls would have disrupted the attacker’s ability to pivot, exfiltrate data, or deploy ransomware. These controls enforce least privilege, block unauthorized internal communications, and provide robust detection and visibility against credential abuse and lateral movement.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid detection and alerting would flag suspicious downloads and access patterns.
Control: Encrypted Traffic (HPE)
Mitigation: Prevents interception of service account credentials in transit and enforces strong encryption standards.
Control: Zero Trust Segmentation
Mitigation: Lateral movement is blocked by granular identity-based network segmentation.
Control: Cloud Firewall (ACF) with Inline IPS (Suricata)
Mitigation: Detects and blocks suspicious command and control traffic in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized data exfiltration attempts are detected and blocked at the network edge.
Rapid anomaly detection can facilitate response before widespread encryption occurs.
Impact at a Glance
Affected Business Functions
- Emergency Services
- Patient Records Management
- Appointment Scheduling
- Billing and Insurance Processing
Estimated downtime: 30 days
Estimated loss: $1,800,000,000
Personal and medical information of approximately 5.6 million individuals, including Social Security numbers, medical records, and insurance details, were compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Replace legacy/weak encryption (e.g., RC4 in Kerberos) and enforce strong encryption standards for all authentication traffic.
- • Deploy Zero Trust Segmentation and least-privilege access controls to prohibit unauthorized lateral movement.
- • Mandate comprehensive egress filtering and FQDN-based policy enforcement to prevent data exfiltration and block command and control channels.
- • Implement continuous anomaly detection and threat monitoring for early identification of credential abuse, privilege escalation, and ransomware behaviors.
- • Enhance visibility and auditability across multicloud networks with unified control planes to detect policy gaps and respond swiftly to attacks.



