logo

BlackCat Goes Dark After Ripping Off Change Healthcare Ransom

ID: 5b1639b4-8b7d-597d-b463-d9d2a5d04343

STIX ID: report--5b1639b4-8b7d-597d-b463-d9d2a5d04343

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-03-05

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

The report covers the BlackCat/ALPHV ransomware attack on Change Healthcare, noting a reported $22M ransom payment, allegations that BlackCat administrators stole affiliate payouts, a threatened leak of 4TB of stolen partner data, and signs the group may be executing an exit scam (shutting its leak site and offering RaaS source code for sale), with broad implications for victims, affiliates, and trust in the RaaS ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.