Security

Black Basta Ransomware Resurfaces, Hits 14 Hospitals in Four Days via Microsoft Teams Phishing

The group has shifted to a Microsoft Teams-based initial-access technique, posing as IT helpdesk staff in direct messages. Three of the targeted hospitals are in critical-condition status, HHS has confirmed.

D
By Daniel Kim Security Reporter
July 29, 2026 / 6 min read

The Black Basta ransomware group has resurfaced with a new initial-access technique that uses Microsoft Teams direct messages, and has compromised 14 hospitals across the United States in the past four days, according to advisories published on Tuesday by the Department of Health and Human Services and by researchers at Trend Micro.

How the Attack Works

The group is sending direct Teams messages to administrative and clinical staff at target hospitals, posing as the internal IT helpdesk. The message contains a «fix» for a fabricated printer issue, which is in fact a remote-access tool that establishes a foothold on the user's endpoint. From there, the attackers move laterally to file shares and to the electronic-health-record environment, exfiltrate patient data, and then deploy the encryptor.

「This is the first time we've seen Black Basta run a fully Teams-native initial-access operation. The social engineering is good enough that two of the targeted hospitals had their helpdesk channels reviewed by us and the messages still passed the smell test,」 said a researcher at Trend Micro's incident-response team.

Severity

HHS has confirmed that three of the 14 affected hospitals are in «critical-condition» status, with elective procedures cancelled and emergency departments operating on paper systems. The American Hospital Association has activated its national incident-coordination protocol for the first time since the 2024 Change Healthcare outage. There is no public statement yet on whether a ransom has been paid by any of the affected organizations.

What Defenders Should Do

Microsoft has published a hardening guide for Teams that includes disabling external chat where possible, blocking file transfers from non-domain accounts, and enforcing second-factor verification for any user account that can send chat invitations. CISA has issued an emergency directive requiring all federal civilian executive-branch agencies to apply the Teams hardening guide within 72 hours.

The Black Basta leak site, which went dark in late 2024, has been updated with the 14 hospital names as of Tuesday morning.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.