A ransomware attack on UnitedHealth subsidiary Change Healthcare crippled prescription processing, billing, and claims services across the U.S., leaving pharmacies, hospitals, doctors, and therapists unable to process insurance transactions and creating severe cash-flow problems for providers. UnitedHealth disclosed the intrusion after isolating affected systems, and the ALPHV/BlackCat gang later claimed responsibility, saying it stole terabytes of data from the company’s environment. The outage highlighted Change Healthcare’s central role in the health sector, where it processes a huge share of medical and pharmacy transactions.
UnitedHealth later acknowledged paying a ransom reportedly worth about $22 million in bitcoin, but the extortion did not end there: a second group, RansomHub, claimed it had obtained the stolen files and began leaking patient data online. Subsequent reporting said the breach likely included highly sensitive personal and health information, potentially affecting U.S. service members and eventually tens of millions of Americans, with later estimates rising to 100 million and then 193 million victims. Investigators and executives also said the attackers entered through a Citrix portal without MFA, turning the incident into one of the largest and most consequential healthcare data breaches on record.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On April 6, 2026, the Iowa attorney general filed a lawsuit against Change Healthcare over the 2024 data breach. The suit represented a new legal action stemming from the incident.
By August 7, 2025, reporting said the Change Healthcare data breach victim count had risen to 193 million. The updated figure significantly expanded the known scope of the incident.
On October 25, 2024, reporting said the Change Healthcare breach affected 100 million Americans, setting a new record for a healthcare data breach. This marked a major escalation in the disclosed scale of victim impact.
At a May 1, 2024 congressional hearing, UnitedHealth CEO Andrew Witty said data stolen in the Change Healthcare attack likely included information on U.S. service members. Lawmakers described the breach as a national security threat during the hearing.
UnitedHealth disclosed that attackers accessed Change Healthcare through a Citrix remote access portal that did not have multifactor authentication enabled. The revelation provided a key technical detail about the initial compromise path.
UnitedHealth Group later confirmed it paid a ransom following the February 2024 cyberattack on Change Healthcare. Reporting tied the payment to roughly $22 million in bitcoin and said the company was monitoring for any public leak of stolen data.
By mid-April 2024, stolen Change Healthcare data was reported leaked by the RansomHub gang after a second extortion threat emerged. Reporting said RansomHub claimed control of more than 4TB of data after ALPHV allegedly failed to share ransom proceeds with affiliates.
On February 28, 2024, the ALPHV/BlackCat ransomware group publicly claimed responsibility for the attack on Change Healthcare. The group said it had stolen more than 6 terabytes of data and disputed UnitedHealth's earlier characterization of the incident.
The Change Healthcare incident caused company-wide connectivity problems and outages that delayed prescription processing and insurance billing at pharmacies across the United States. UnitedHealth said the disruption was specific to Change Healthcare while other UnitedHealth systems remained operational.
On February 21, 2024, UnitedHealth Group disclosed that it identified a suspected nation-state-associated threat actor with access to some Change Healthcare IT systems. The company said it immediately isolated affected systems, engaged security experts, coordinated with law enforcement, and notified customers and government agencies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
beckershospitalreview.com
Open sourcetechtarget.com
Open sourcecyberscoop.com
Open sourceblackfog.com
Open sourcecyberscoop.com
Open sourcecnn.com
Open sourcecbsnews.com
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.