CASE DOSSIER
alleged
ALPHV / BlackCat Ransomware Attack on Change Healthcare
Docket: SEC CIK 0000731766 Court: U.S. District Court for the District of Minnesota Opened: 2024-02-21 Sector: Healthcare and Public Health
Key Facts
Status
ALLEGED
Legal disposition
Loss Amount
$2.5 billion
UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.
Techniques
5
Verified mappings
Defendants
0
Named in charges
- Legal Status: ALLEGED in U.S. District Court for the District of Minnesota.
- Primary Target Sector: Healthcare and Public Health.
- Documented Financial Loss: $2.5 billion.
- 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.
Procedural & Incident Timeline
2024-02-21 disclosure
UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems.
2024-02-27 advisory
CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion.
2024-04-22 disclosure
UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication." | Senate Finance Committee Testimony ¶ 4 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways." | SEC Form 8-K Item 1.05 | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom." | SEC Form 8-K Disclosure | reviewed |
| T1133 | External Remote Services Initial Access | "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls." | UnitedHealth Senate Testimony ¶ 5 | reviewed |
| T1087 | Account Discovery Discovery | "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts." | CISA Advisory AA23-353A ¶ 7 | reviewed |
View 1 Proposed / Unverified Mapping Candidates
T1041: Exfiltration Over C2 Channel Proposed by rule
"Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery."
CISA Cybersecurity Advisories
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, ALPHV / BlackCat Ransomware Attack on Change Healthcare, No. SEC CIK 0000731766 (U.S. District Court for the District of Minnesota 2024), https://cyberattackcaselibrary.pages.dev/cases/alphv-blackcat-change-healthcare/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/alphv-blackcat-change-healthcare" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>