DISH Network disclosed on 23 February 2023 a network outage affecting internal servers and IT telephony. The disruption ran for several days across dish.com, the Dish Anywhere application, Boost Mobile and other properties.
In a securities filing on 28 February the company confirmed the outage resulted from a ransomware attack. It separately stated that on 27 February it became aware that data had been extracted from its systems, and that the investigation might show the extracted data included personal information.
The Telephony Went Down With Everything Else
The detail worth holding is that IT telephony was among the affected systems. A customer whose service was disrupted could not reach the company about it, because the mechanism for reaching the company was part of the same incident.
The corpus records the same compounding at 25-1127b, where telephone systems went down at three London councils. Communications infrastructure is the thing an organisation needs most during an incident and is rarely segmented from the estate the incident is in.
Data Theft Was Established Four Days After The Outage
The sequence is instructive: outage on the 23rd, awareness of extraction on the 27th, ransomware confirmed publicly on the 28th. The availability failure was visible immediately; the data question took days and was still hedged when disclosed.
The corpus notes at 26-0403 that securities disclosure clocks and forensic investigation run on incompatible timescales. This file shows what that produces — a filing that reports a possibility because a certainty is not yet available.
What This File Does Not Carry
Figures circulated at the time for the number of individuals affected. This desk has not established one from a source it can cite and records none.
That is a gap rather than a finding, and the desk would rather show the gap than fill it with a number whose provenance it cannot state.
Built on contemporaneous reporting of DISH Network’s disclosures and securities filings. The 23 February outage, the affected properties, the 27 February awareness of data extraction and the 28 February confirmation of ransomware are the company’s own statements as reported. No count of affected individuals is asserted: figures circulated in reporting at the time, and this desk has not established one against a source it can cite. No actor attribution is made. No indicators are reproduced. Graded high on the outage and the filings. Corrections: corrections@forensicpost.com.
- Dish Network confirms ransomware attack behind multi-day outageBleepingComputer
- Dish Network Confirms Ransomware OutageInfosecurity Magazine