CASE DOSSIER convicted

Change Healthcare Ransomware Outage (ALPHV / BlackCat)

Docket: HHS-OCR-2024-001 Court: U.S. House Energy and Commerce Committee Oversight & HHS OCR Opened: 2024-02-21 Sector: Healthcare, Financial Services

Key Facts

Status
CONVICTED
Legal disposition
Loss Amount
$3.0 billion
Over $3 billion in direct incident response, provider loan liquidity, forensic remediation, and $22M Bitcoin ransom payment.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: CONVICTED in U.S. House Energy and Commerce Committee Oversight & HHS OCR.
  • Primary Target Sector: Healthcare, Financial Services.
  • Documented Financial Loss: $3.0 billion.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Attackers logged into a remote access Citrix portal utilizing single-factor employee credentials harvested by infostealers. The portal was a legacy environment that lacked multi-factor authentication (MFA) enforcement.

Operational & Financial Fallout

Crippled billing and claims processing for over 50% of the medical claims in the United States. Pharmacies could not verify prescription insurance coverage, forcing patients to pay out-of-pocket. Over $3 billion in direct response, provider emergency loan liquidity, and forensic reconstruction costs.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CONVICTED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Attackers logged into a remote access Citrix portal utilizing single-factor employee credentials harvested by infostealers. The portal was a legacy environment that lacked multi-factor authentication (MFA) enforcement.

Adversary Kill Chain Flow

4 Documented Phases
1
Initial Access Unauthenticated Citrix Portal Ingress
MITRE ATT&CK T1078 →

ALPHV/BlackCat affiliates logged into a Change Healthcare Citrix application server using stolen credentials that lacked secondary MFA verification.

Artifacts & Tooling: Citrix NetScaler Gateway Single-factor employee session Infostealer credential logs
2
Lateral Movement & Recon Active Directory Discovery and Network Mapping
MITRE ATT&CK T1087 →

Adversaries traversed from the Citrix boundary across internal subnets using standard administrative tools and harvested Kerberos tickets to locate production databases.

Artifacts & Tooling: AdFind.exe BloodHound / SharpHound Kerberos ticket extraction
3
Data Exfiltration Cloud Staging of 6 Terabytes of Protected Health Information
MITRE ATT&CK T1567 →

Operatives archived patient records, claims histories, and clinical data into encrypted 7zip volumes and exfiltrated them to cloud hosting accounts via Megasync.

Artifacts & Tooling: 7-Zip compressed archives Megasync cloud client 6 TB health data exfiltrated
4
Extortion Detonation ALPHV Rust-based Ransomware Encryption
MITRE ATT&CK T1486 →

Attackers triggered the ALPHV (BlackCat) Rust binary across critical database servers, encrypting virtual machines and appending random extensions, halting claims processing nationwide.

Artifacts & Tooling: ALPHV Rust executable Esxi-targeted payload RECOVER-files.txt ransom notes
Real-World Blast Radius & Operational Fallout

Crippled billing and claims processing for over 50% of the medical claims in the United States. Pharmacies could not verify prescription insurance coverage, forcing patients to pay out-of-pocket. Over $3 billion in direct response, provider emergency loan liquidity, and forensic reconstruction costs.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Mandate phishing-resistant multi-factor authentication across 100% of external remote access gateways without exceptions for legacy portals.
✓ Implement automated cloud data egress monitoring to alert on outbound exfiltration exceeding baseline volumes.
✓ Maintain immutable, logically isolated operational recovery environments for core transactional clearinghouse services.
✓ Segment clinical and pharmacy transactional systems strictly from enterprise administrative domains.

Procedural & Incident Timeline

2024-02-12 incident

Attackers gain initial access to Change Healthcare Citrix portal lacking multi-factor authentication.

2024-02-21 incident

ALPHV ransomware payload executes across server farms; medical claims processing goes dark nationwide.

2024-03-01 ransom_payment

UnitedHealth Group authorizes payment of 350 Bitcoin (approx. $22M) to the ALPHV affiliate operator.

2024-05-01 hearing

UnitedHealth CEO testifies before Congress, confirming the root cause was an unauthenticated Citrix portal.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Attackers logged into a production Citrix remote access portal using compromised employee credentials that were not protected by multi-factor authentication." Congressional Hearing Testimony of UnitedHealth Group CEO Andrew Witty, May 1, 2024 reviewed
T1486 Data Encrypted for Impact
Impact
"ALPHV/BlackCat ransomware encrypted core production enterprise databases and virtualization hosts, completely severing real-time pharmacy eligibility checks across the U.S." HHS OCR Formal Breach Notification reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Adversaries exfiltrated approximately 6 terabytes of highly confidential medical claims, patient clinical history, and billing records to cloud storage repositories prior to encryption." UnitedHealth Group 8-K Regulatory Filing reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Change Healthcare Ransomware Outage (ALPHV / BlackCat), No. HHS-OCR-2024-001 (U.S. House Energy and Commerce Committee Oversight & HHS OCR 2024), https://cybercaselibrary.com/cases/change-healthcare-blackcat-ransomware/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/change-healthcare-blackcat-ransomware" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>