CASE DOSSIER alleged

ALPHV / BlackCat Ransomware Attack on Change Healthcare

Docket: SEC CIK 0000731766 Court: U.S. District Court for the District of Minnesota Opened: 2024-02-21 Sector: Healthcare and Public Health

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$2.5 billion
UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.
Techniques
5
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the District of Minnesota.
  • Primary Target Sector: Healthcare and Public Health.
  • Documented Financial Loss: $2.5 billion.
  • 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Stolen credentials used to enter an unsegmented Citrix remote access portal lacking multifactor authentication, combined with exploitation of ScreenConnect (CVE-2024-1709) for persistence.

Operational & Financial Fallout

Disrupted 1 in every 3 medical prescriptions in the United States. Pharmacies were unable to process electronic insurance claims, military medical clinics were forced into manual paper forms, and hospital systems suffered severe cash flow crunches totaling over $2 billion. Change Healthcare paid a 350 BTC ($22M) ransom.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: ALLEGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Stolen credentials used to enter an unsegmented Citrix remote access portal lacking multifactor authentication, combined with exploitation of ScreenConnect (CVE-2024-1709) for persistence.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Single-Factor Citrix Remote Access Breach
MITRE ATT&CK T1078 →

The ALPHV affiliate authenticated into Change Healthcare internal networks through an unpatched Citrix gateway using valid corporate credentials that lacked multifactor authentication.

Artifacts & Tooling: Citrix Gateway portal Single-factor employee login
2
Persistence & Tooling ScreenConnect Remote Administration Deployment
MITRE ATT&CK T1133 →

Threat actors established persistent secondary footholds using legitimate ScreenConnect remote monitoring agents, ensuring continuous access even if primary credentials were changed.

Artifacts & Tooling: ScreenConnect client CVE-2024-1709
3
Reconnaissance & Privilege Escalation Claims Database and Protected Health Information Enumeration
MITRE ATT&CK T1083 →

Affiliates spent nine days surveying network shares and cloud environments, targeting database servers storing patient records, Medicare claims, and billing logs.

Artifacts & Tooling: PowerView scripts Database enumeration
4
Exfiltration Six-Terabyte Medical Record Exfiltration
MITRE ATT&CK T1567 →

Using high-speed multithreaded file transfer utilities, attackers exfiltrated approximately 6 terabytes of confidential health data and personal identifying information to offshore servers.

Artifacts & Tooling: Exfiltration tools 6TB medical database dump
5
Execution & Double Extortion ALPHV Rust Ransomware Detonation & Affiliate Mutiny
MITRE ATT&CK T1486 →

The affiliate launched the high-performance ALPHV Rust ransomware, encrypting virtual machines and data volumes. After Change Healthcare paid $22 million, the ALPHV core operator pocketed the funds and executed an exit scam, triggering affiliate threats to leak the data.

Artifacts & Tooling: ALPHV.exe (Rust) Tor negotiation portal
Real-World Blast Radius & Operational Fallout

Disrupted 1 in every 3 medical prescriptions in the United States. Pharmacies were unable to process electronic insurance claims, military medical clinics were forced into manual paper forms, and hospital systems suffered severe cash flow crunches totaling over $2 billion. Change Healthcare paid a 350 BTC ($22M) ransom.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce hardware-backed MFA across every remote access gateway and vendor integration point.
✓ Restrict remote monitoring and management (RMM) software like ScreenConnect to explicit, monitored jump hosts.
✓ Maintain immutable, write-once-read-many (WORM) storage for critical healthcare transaction databases.
✓ Deploy real-time DLP detection rules for abnormal bulk egress transfers.

Procedural & Incident Timeline

2024-02-21 disclosure

UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems.

2024-02-27 advisory

CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion.

2024-04-22 disclosure

UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication." Senate Finance Committee Testimony ¶ 4 reviewed
T1486 Data Encrypted for Impact
Impact
"ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways." SEC Form 8-K Item 1.05 reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom." SEC Form 8-K Disclosure reviewed
T1133 External Remote Services
Initial Access
"Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls." UnitedHealth Senate Testimony ¶ 5 reviewed
T1087 Account Discovery
Discovery
"ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts." CISA Advisory AA23-353A ¶ 7 reviewed
View 1 Proposed / Unverified Mapping Candidates
T1041: Exfiltration Over C2 Channel Proposed by rule

"Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery."

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, ALPHV / BlackCat Ransomware Attack on Change Healthcare, No. SEC CIK 0000731766 (U.S. District Court for the District of Minnesota 2024), https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/alphv-blackcat-change-healthcare" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>