CASE DOSSIER alleged

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Docket: SEC CIK 0000731766 Court: U.S. District Court for the District of Minnesota Opened: 2024-02-21 Sector: Healthcare and Public Health

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$2.5 billion
UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.
Techniques
5
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the District of Minnesota.
  • Primary Target Sector: Healthcare and Public Health.
  • Documented Financial Loss: $2.5 billion.
  • 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.

Procedural & Incident Timeline

2024-02-21 disclosure

UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems.

2024-02-27 advisory

CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion.

2024-04-22 disclosure

UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication." Senate Finance Committee Testimony ¶ 4 reviewed
T1486 Data Encrypted for Impact
Impact
"ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways." SEC Form 8-K Item 1.05 reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom." SEC Form 8-K Disclosure reviewed
T1133 External Remote Services
Initial Access
"Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls." UnitedHealth Senate Testimony ¶ 5 reviewed
T1087 Account Discovery
Discovery
"ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts." CISA Advisory AA23-353A ¶ 7 reviewed
View 1 Proposed / Unverified Mapping Candidates
T1041: Exfiltration Over C2 Channel Proposed by rule

"Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery."

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, ALPHV / BlackCat Ransomware Attack on Change Healthcare, No. SEC CIK 0000731766 (U.S. District Court for the District of Minnesota 2024), https://cyberattackcaselibrary.pages.dev/cases/alphv-blackcat-change-healthcare/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/alphv-blackcat-change-healthcare" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>