logo

How the ransomware attack at Change Healthcare went down: A timeline

ID: 8482de38-ffbb-53d6-9938-e98513e88f07

STIX ID: report--8482de38-ffbb-53d6-9938-e98513e88f07

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2024-08-17

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

In February 2024 Change Healthcare—a major U.S. medical billing and claims processor owned by UnitedHealth—was hit by a ransomware attack attributed to ALPHV/BlackCat affiliates that disrupted healthcare billing systems nationwide, resulted in a reported $22M ransom payment, and led to the theft and subsequent extortion publication of highly sensitive medical and personal data affecting up to 190 million Americans; the attackers used compromised credentials lacking multi‑factor authentication and poor network segmentation to move within systems, and follow-on extortion by an affiliate (RansomHub) and legal and government responses followed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.