logo

Change Healthcare lists the medical data stolen in ransomware attack

ID: 8b0114e9-f4fd-5118-b4ee-35241c6e0d36

STIX ID: report--8b0114e9-f4fd-5118-b4ee-35241c6e0d36

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-06-21

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

UnitedHealth confirmed that a February ransomware attack on its Change Healthcare subsidiary, attributed to the BlackCat/ALPHV group, resulted in the theft of approximately 6 TB of data containing health insurance, medical, billing, and personal identifiers for a substantial portion of Americans (CEO estimated up to ~1/3). The incident caused nationwide healthcare billing outages, involved stolen credentials and lack of MFA on Citrix, included at least one ransom payment (reported ~$22M) and subsequent leaking/demand activity on a data-leak site, and has produced over $872M in losses to date; affected individuals will receive breach notifications and offered credit monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.