Change Healthcare hackers broke in using stolen credentials — and no MFA, says UHG CEO
ID: 7a964ead-bf1b-5bfb-a281-d4b15595e04b
STIX ID: report--7a964ead-bf1b-5bfb-a281-d4b15595e04b
Feed Name: TechCrunch Security News
Threat Score
UnitedHealth disclosed that the February ransomware attack on Change Healthcare involved attackers using compromised credentials to access an unprotected Citrix portal (no MFA), move laterally, exfiltrate terabytes of health data affecting a substantial portion of Americans, and deploy ransomware (claimed by RansomHub); UnitedHealth paid a ransom and reported over $870M in related costs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
