Single Citrix Compromised Credential Results in $22,000,000 Ransom to Change Healthcare
ID: e5e1e269-b206-5378-a968-6f8e1a1263bc
STIX ID: report--e5e1e269-b206-5378-a968-6f8e1a1263bc
Feed Name: infostealers.com
Threat Score
In February 2024 Change Healthcare was hit by a BlackCat ransomware attack that began when an employee’s Citrix credentials were stolen via an infostealer after downloading a file from Mega.nz; the portal lacked MFA, attackers moved laterally, exfiltrated data, and deployed ransomware, causing major platform disruption and an estimated $872M impact plus a $22M ransom payment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
