logo

Change Healthcare hacked using stolen Citrix account with no MFA

ID: 1fd2bae9-33be-5a52-bc34-a66c6a5a033c

STIX ID: report--1fd2bae9-33be-5a52-bc34-a66c6a5a033c

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

UnitedHealth confirmed that Change Healthcare was breached by the ALPHV/BlackCat ransomware operation in mid-February 2024 after attackers used stolen Citrix credentials (on a portal without MFA) to access and move laterally within systems; ransomware was deployed on February 21, causing widespread disruptions to billing, prescriptions, and payment processing, exposure of PHI/PII, an estimated $872M loss, and subsequent ransom/extortion activity, with post-incident remediation including credential rotations and complete rebuilds of core services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.