ALPHV / BlackCat Ransomware Attack on Change Healthcare
Key Facts
- Legal Status: ALLEGED in U.S. District Court for the District of Minnesota.
- Primary Target Sector: Healthcare and Public Health.
- Documented Financial Loss: $2.5 billion.
- 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Stolen credentials used to enter an unsegmented Citrix remote access portal lacking multifactor authentication, combined with exploitation of ScreenConnect (CVE-2024-1709) for persistence.
Operational & Financial Fallout
Disrupted 1 in every 3 medical prescriptions in the United States. Pharmacies were unable to process electronic insurance claims, military medical clinics were forced into manual paper forms, and hospital systems suffered severe cash flow crunches totaling over $2 billion. Change Healthcare paid a 350 BTC ($22M) ransom.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Stolen credentials used to enter an unsegmented Citrix remote access portal lacking multifactor authentication, combined with exploitation of ScreenConnect (CVE-2024-1709) for persistence.
Adversary Kill Chain Flow
5 Documented PhasesThe ALPHV affiliate authenticated into Change Healthcare internal networks through an unpatched Citrix gateway using valid corporate credentials that lacked multifactor authentication.
Threat actors established persistent secondary footholds using legitimate ScreenConnect remote monitoring agents, ensuring continuous access even if primary credentials were changed.
Affiliates spent nine days surveying network shares and cloud environments, targeting database servers storing patient records, Medicare claims, and billing logs.
Using high-speed multithreaded file transfer utilities, attackers exfiltrated approximately 6 terabytes of confidential health data and personal identifying information to offshore servers.
The affiliate launched the high-performance ALPHV Rust ransomware, encrypting virtual machines and data volumes. After Change Healthcare paid $22 million, the ALPHV core operator pocketed the funds and executed an exit scam, triggering affiliate threats to leak the data.
Disrupted 1 in every 3 medical prescriptions in the United States. Pharmacies were unable to process electronic insurance claims, military medical clinics were forced into manual paper forms, and hospital systems suffered severe cash flow crunches totaling over $2 billion. Change Healthcare paid a 350 BTC ($22M) ransom.
Procedural & Incident Timeline
UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems.
CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion.
UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication." | Senate Finance Committee Testimony ¶ 4 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways." | SEC Form 8-K Item 1.05 | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom." | SEC Form 8-K Disclosure | reviewed |
| T1133 | External Remote Services Initial Access | "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls." | UnitedHealth Senate Testimony ¶ 5 | reviewed |
| T1087 | Account Discovery Discovery | "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts." | CISA Advisory AA23-353A ¶ 7 | reviewed |
View 1 Proposed / Unverified Mapping Candidates
"Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery."