Desk live·
ForensicPost
Ransomware/Availability/File 23-0223

Dish Network Customers Spent Days Unable to Reach a Company That Could Not Reach Itself

Internal servers and IT telephony went down on a Friday and stayed down. The company confirmed ransomware in a securities filing five days later, and separately became aware that data had been taken — but the visible harm was a support line nobody could get through.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDISH Network
ActorUnattributed
S. Rosler10 min readConfidence: high2 sources reviewed

DISH Network disclosed on 23 February 2023 a network outage affecting internal servers and IT telephony. The disruption ran for several days across dish.com, the Dish Anywhere application, Boost Mobile and other properties.

In a securities filing on 28 February the company confirmed the outage resulted from a ransomware attack. It separately stated that on 27 February it became aware that data had been extracted from its systems, and that the investigation might show the extracted data included personal information.

The Telephony Went Down With Everything Else

The detail worth holding is that IT telephony was among the affected systems. A customer whose service was disrupted could not reach the company about it, because the mechanism for reaching the company was part of the same incident.

The corpus records the same compounding at 25-1127b, where telephone systems went down at three London councils. Communications infrastructure is the thing an organisation needs most during an incident and is rarely segmented from the estate the incident is in.

Data Theft Was Established Four Days After The Outage

The sequence is instructive: outage on the 23rd, awareness of extraction on the 27th, ransomware confirmed publicly on the 28th. The availability failure was visible immediately; the data question took days and was still hedged when disclosed.

The corpus notes at 26-0403 that securities disclosure clocks and forensic investigation run on incompatible timescales. This file shows what that produces — a filing that reports a possibility because a certainty is not yet available.

What This File Does Not Carry

Figures circulated at the time for the number of individuals affected. This desk has not established one from a source it can cite and records none.

That is a gap rather than a finding, and the desk would rather show the gap than fill it with a number whose provenance it cannot state.

How we reported this

Built on contemporaneous reporting of DISH Network’s disclosures and securities filings. The 23 February outage, the affected properties, the 27 February awareness of data extraction and the 28 February confirmation of ransomware are the company’s own statements as reported. No count of affected individuals is asserted: figures circulated in reporting at the time, and this desk has not established one against a source it can cite. No actor attribution is made. No indicators are reproduced. Graded high on the outage and the filings. Corrections: corrections@forensicpost.com.

Sources
  1. Dish Network confirms ransomware attack behind multi-day outageBleepingComputer
  2. Dish Network Confirms Ransomware OutageInfosecurity Magazine
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary