Extortion group threatens to sell Change Healthcare data
ID: 8400efdf-e075-5e8c-88f9-f615ada21c56
STIX ID: report--8400efdf-e075-5e8c-88f9-f615ada21c56
Feed Name: CyberScoop
The report covers the Feb. 21 ransomware attack on Change Healthcare attributed to ALPHV/BlackCat and an affiliate called “notchy,” who claim possession of 4–6 TB of stolen data; after a reported $22M ransom payment (which was subsequently moved and laundered), a new dark‑web auction site RansomHub is threatening to sell over 4 TB of the data unless Change Healthcare/UnitedHealth Group pays by a set deadline. The article highlights internal disputes among criminal actors, the emergence of RansomHub (operated by “koley”) recruiting affiliates, and active data‑extortion activity affecting the U.S. healthcare sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
