The American satellite broadcast provider Dish Network went offline, the outage impacted Dish.com, Dish Anywhere app, and many other services owned by the company.
The threat actors initially compromised the company’s Windows domain controllers and then encrypted the VMware ESXi servers and backups.
Now the Satellite TV giant has started notifying the impacted 296,851 individuals.
The company pointed out that there is no evidence of misuse of stolen information and confirmed that its customer databases were not accessed.
It was found that the company paid a ransom to avoid their data being leaked online, in fact, it highlights that it has received confirmation that the extracted data has been delete.
Source: https://securityaffairs.com/146515/cyber-crime/dish-network-disclosed-data-breach.html
TPRM report: https://scoringcyber.rankiteo.com/company/dish-network
"id": "dis03212623",
"linkid": "dish-network",
"type": "Ransomware",
"date": "05/2023",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 296851,
'industry': 'Satellite Broadcasting',
'location': 'United States',
'name': 'Dish Network',
'type': 'Company'}],
'attack_vector': 'Compromised Windows domain controllers',
'description': 'The American satellite broadcast provider Dish Network went '
'offline, the outage impacted Dish.com, Dish Anywhere app, and '
'many other services owned by the company. The threat actors '
'initially compromised the company’s Windows domain '
'controllers and then encrypted the VMware ESXi servers and '
'backups. Now the Satellite TV giant has started notifying the '
'impacted 296,851 individuals. The company pointed out that '
'there is no evidence of misuse of stolen information and '
'confirmed that its customer databases were not accessed. It '
'was found that the company paid a ransom to avoid their data '
'being leaked online, in fact, it highlights that it has '
'received confirmation that the extracted data has been '
'deleted.',
'impact': {'data_compromised': 'VMware ESXi servers and backups',
'operational_impact': 'Services went offline',
'systems_affected': ['Dish.com',
'Dish Anywhere app',
'Other services owned by the company']},
'motivation': 'Ransom',
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransom_paid': True},
'title': 'Dish Network Ransomware Attack',
'type': 'Ransomware'}