{
  "id": "case-alphv-change-healthcare",
  "slug": "alphv-blackcat-change-healthcare",
  "title": "ALPHV / BlackCat Ransomware Attack on Change Healthcare",
  "summary": "Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.",
  "case_number": "SEC CIK 0000731766",
  "court": "U.S. District Court for the District of Minnesota",
  "district": "D. Minn.",
  "country": "United States",
  "opened_at": "2024-02-21",
  "status": "alleged",
  "victim_sector": "Healthcare and Public Health",
  "victim_country": "United States",
  "loss_amount_usd": 2450000000,
  "loss_amount_note": "UnitedHealth Group reported over $2.45 billion in direct response costs, loan advances to providers, and forensic investigations, plus a paid $22 million Bitcoin ransom.",
  "first_seen_at": "2024-02-12T00:00:00Z",
  "last_updated_at": "2026-09-19T16:00:00Z",
  "actor_slug": "alphv-blackcat",
  "defendant_slugs": [],
  "cves": [
    "CVE-2024-1709"
  ],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication.",
      "evidence_locator": "Senate Finance Committee Testimony \u00b6 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Congressional Testimony by UnitedHealth CEO",
      "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways.",
      "evidence_locator": "SEC Form 8-K Item 1.05",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "UnitedHealth Group Form 8-K Item 1.05",
      "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom.",
      "evidence_locator": "SEC Form 8-K Disclosure",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "UnitedHealth Group SEC Filing",
      "source_url": "https://www.sec.gov/ix?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery.",
      "evidence_locator": "HHS OCR Notice",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "HHS Office for Civil Rights Breach Notice",
      "source_url": "https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1133",
      "evidence_excerpt": "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls.",
      "evidence_locator": "UnitedHealth Senate Testimony \u00b6 5",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Senate Testimony",
      "source_url": "https://www.finance.senate.gov/hearings/hacking-healthcare-examining-the-change-healthcare-cyberattack",
      "technique_name": "External Remote Services",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1087",
      "evidence_excerpt": "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts.",
      "evidence_locator": "CISA Advisory AA23-353A \u00b6 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-353A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a",
      "technique_name": "Account Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "disclosure",
      "event_date": "2024-02-21",
      "description": "UnitedHealth Group files Form 8-K Item 1.05 reporting cybersecurity incident affecting Change Healthcare systems."
    },
    {
      "event_type": "advisory",
      "event_date": "2024-02-27",
      "description": "CISA and FBI update Joint Advisory AA23-353A with technical indicators from ALPHV BlackCat Change Healthcare intrusion."
    },
    {
      "event_type": "disclosure",
      "event_date": "2024-04-22",
      "description": "UnitedHealth Group issues public statement acknowledging payment of $22 million extortion ransom to protect patient data."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Stolen credentials used to enter an unsegmented Citrix remote access portal lacking multifactor authentication, combined with exploitation of ScreenConnect (CVE-2024-1709) for persistence.",
    "blast_radius": "Disrupted 1 in every 3 medical prescriptions in the United States. Pharmacies were unable to process electronic insurance claims, military medical clinics were forced into manual paper forms, and hospital systems suffered severe cash flow crunches totaling over $2 billion. Change Healthcare paid a 350 BTC ($22M) ransom.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Single-Factor Citrix Remote Access Breach",
        "description": "The ALPHV affiliate authenticated into Change Healthcare internal networks through an unpatched Citrix gateway using valid corporate credentials that lacked multifactor authentication.",
        "technical_artifacts": [
          "Citrix Gateway portal",
          "Single-factor employee login"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Persistence & Tooling",
        "title": "ScreenConnect Remote Administration Deployment",
        "description": "Threat actors established persistent secondary footholds using legitimate ScreenConnect remote monitoring agents, ensuring continuous access even if primary credentials were changed.",
        "technical_artifacts": [
          "ScreenConnect client",
          "CVE-2024-1709"
        ],
        "mitre_technique_id": "T1133"
      },
      {
        "phase": "Reconnaissance & Privilege Escalation",
        "title": "Claims Database and Protected Health Information Enumeration",
        "description": "Affiliates spent nine days surveying network shares and cloud environments, targeting database servers storing patient records, Medicare claims, and billing logs.",
        "technical_artifacts": [
          "PowerView scripts",
          "Database enumeration"
        ],
        "mitre_technique_id": "T1083"
      },
      {
        "phase": "Exfiltration",
        "title": "Six-Terabyte Medical Record Exfiltration",
        "description": "Using high-speed multithreaded file transfer utilities, attackers exfiltrated approximately 6 terabytes of confidential health data and personal identifying information to offshore servers.",
        "technical_artifacts": [
          "Exfiltration tools",
          "6TB medical database dump"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Execution & Double Extortion",
        "title": "ALPHV Rust Ransomware Detonation & Affiliate Mutiny",
        "description": "The affiliate launched the high-performance ALPHV Rust ransomware, encrypting virtual machines and data volumes. After Change Healthcare paid $22 million, the ALPHV core operator pocketed the funds and executed an exit scam, triggering affiliate threats to leak the data.",
        "technical_artifacts": [
          "ALPHV.exe (Rust)",
          "Tor negotiation portal"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce hardware-backed MFA across every remote access gateway and vendor integration point.",
      "Restrict remote monitoring and management (RMM) software like ScreenConnect to explicit, monitored jump hosts.",
      "Maintain immutable, write-once-read-many (WORM) storage for critical healthcare transaction databases.",
      "Deploy real-time DLP detection rules for abnormal bulk egress transfers."
    ]
  }
}