{
  "id": "case-alphv-change-healthcare",
  "slug": "alphv-blackcat-change-healthcare",
  "title": "ALPHV / BlackCat Ransomware Attack on Change Healthcare",
  "summary": "Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.",
  "case_number": "SEC CIK 0000731766",
  "court": "U.S. District Court for the District of Minnesota",
  "district": "D. Minn.",
  "country": "United States",
  "opened_at": "2024-02-21",
  "status": "alleged",
  "victim_sector": "Healthcare and Public Health",
  "victim_country": "United States",
  "loss_amount_usd": 2450000000,
  "loss_amount_note": "UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.",
  "first_seen_at": "2024-02-12T00:00:00Z",
  "last_updated_at": "2026-09-19T16:00:00Z",
  "actor_slug": "alphv-blackcat",
  "defendant_slugs": [],
  "cves": [
    "CVE-2024-1709"
  ],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication.",
      "evidence_locator": "Senate Finance Committee Testimony \u00b6 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Congressional Testimony by UnitedHealth CEO",
      "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways.",
      "evidence_locator": "SEC Form 8-K Item 1.05",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "UnitedHealth Group Form 8-K Item 1.05",
      "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom.",
      "evidence_locator": "SEC Form 8-K Disclosure",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "UnitedHealth Group SEC Filing",
      "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery.",
      "evidence_locator": "HHS OCR Notice",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "HHS Office for Civil Rights Breach Notice",
      "source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1133",
      "evidence_excerpt": "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls.",
      "evidence_locator": "UnitedHealth Senate Testimony \u00b6 5",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Senate Testimony",
      "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
      "technique_name": "External Remote Services",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1087",
      "evidence_excerpt": "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts.",
      "evidence_locator": "CISA Advisory AA23-353A \u00b6 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-353A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a",
      "technique_name": "Account Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "disclosure",
      "event_date": "2024-02-21",
      "description": "UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems."
    },
    {
      "event_type": "advisory",
      "event_date": "2024-02-27",
      "description": "CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion."
    },
    {
      "event_type": "disclosure",
      "event_date": "2024-04-22",
      "description": "UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data."
    }
  ]
}