logo

UnitedHealth confirms it paid ransomware gang to stop data leak

ID: f6e21eaa-b0fe-51b2-b6f0-ffe4604e1611

STIX ID: report--f6e21eaa-b0fe-51b2-b6f0-ffe4604e1611

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

UnitedHealth Group confirmed it paid a ransom after a late-February ransomware attack on Optum/Change Healthcare that disrupted payment processing and other healthcare services; threat actors including BlackCat/ALPHV affiliates and RansomHub claim to have stolen large amounts of patient and corporate data (allegedly up to 6TB). The incident caused significant financial impact (reported $872M), visible blockchain ransom payments, ongoing extortion and partial data leaks, and prompted a U.S. government investigation and remedial actions such as notifications and credit monitoring for affected individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.