logo

Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

ID: ab0e8daf-94e5-591f-9d60-d5d6e29a3ca2

STIX ID: report--ab0e8daf-94e5-591f-9d60-d5d6e29a3ca2

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-04-08

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Change Healthcare is reportedly being targeted by a second ransomware/extortion group called RansomHub, which claims to possess 4 TB of the company's data including PII for active US military personnel, medical records, and payment information and is demanding ransom within 12 days. The report links this extortion to a recent ALPHV ransomware incident (with an alleged $22M payment), outlines theories that affiliates retained data or that ALPHV rebranded as RansomHub, and highlights potential operational and regulatory impacts while noting limited public confirmation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.