Change Healthcare Ransomware Outage (ALPHV / BlackCat)
Key Facts
- Legal Status: CONVICTED in U.S. House Energy and Commerce Committee Oversight & HHS OCR.
- Primary Target Sector: Healthcare, Financial Services.
- Documented Financial Loss: $3.0 billion.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Attackers logged into a remote access Citrix portal utilizing single-factor employee credentials harvested by infostealers. The portal was a legacy environment that lacked multi-factor authentication (MFA) enforcement.
Operational & Financial Fallout
Crippled billing and claims processing for over 50% of the medical claims in the United States. Pharmacies could not verify prescription insurance coverage, forcing patients to pay out-of-pocket. Over $3 billion in direct response, provider emergency loan liquidity, and forensic reconstruction costs.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Attackers logged into a remote access Citrix portal utilizing single-factor employee credentials harvested by infostealers. The portal was a legacy environment that lacked multi-factor authentication (MFA) enforcement.
Adversary Kill Chain Flow
4 Documented PhasesALPHV/BlackCat affiliates logged into a Change Healthcare Citrix application server using stolen credentials that lacked secondary MFA verification.
Adversaries traversed from the Citrix boundary across internal subnets using standard administrative tools and harvested Kerberos tickets to locate production databases.
Operatives archived patient records, claims histories, and clinical data into encrypted 7zip volumes and exfiltrated them to cloud hosting accounts via Megasync.
Attackers triggered the ALPHV (BlackCat) Rust binary across critical database servers, encrypting virtual machines and appending random extensions, halting claims processing nationwide.
Crippled billing and claims processing for over 50% of the medical claims in the United States. Pharmacies could not verify prescription insurance coverage, forcing patients to pay out-of-pocket. Over $3 billion in direct response, provider emergency loan liquidity, and forensic reconstruction costs.
Procedural & Incident Timeline
Attackers gain initial access to Change Healthcare Citrix portal lacking multi-factor authentication.
ALPHV ransomware payload executes across server farms; medical claims processing goes dark nationwide.
UnitedHealth Group authorizes payment of 350 Bitcoin (approx. $22M) to the ALPHV affiliate operator.
UnitedHealth CEO testifies before Congress, confirming the root cause was an unauthenticated Citrix portal.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Attackers logged into a production Citrix remote access portal using compromised employee credentials that were not protected by multi-factor authentication." | Congressional Hearing Testimony of UnitedHealth Group CEO Andrew Witty, May 1, 2024 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "ALPHV/BlackCat ransomware encrypted core production enterprise databases and virtualization hosts, completely severing real-time pharmacy eligibility checks across the U.S." | HHS OCR Formal Breach Notification | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Adversaries exfiltrated approximately 6 terabytes of highly confidential medical claims, patient clinical history, and billing records to cloud storage repositories prior to encryption." | UnitedHealth Group 8-K Regulatory Filing | reviewed |