In February 2024 the BlackCat/ALPHV ransomware gang breached Change Healthcare, a UnitedHealth Group subsidiary, in what UnitedHealth confirmed in January 2025 affected approximately 190 million Americans, making it the largest healthcare data breach in U.S. history. The attackers used stolen credentials to access a Citrix remote portal that lacked multi-factor authentication, then exfiltrated roughly 6 TB of data and encrypted internal systems, paralyzing prescription, claims, and billing platforms that U.S. doctors and pharmacies depend on. Stolen records included health insurance information, medical files, billing data, addresses, phone numbers and, in some cases, Social Security and government ID numbers. UnitedHealth paid a reported $22 million ransom for a decryptor and a promise of deletion, but the BlackCat operators executed an exit scam against their own affiliate, who then partnered with RansomHub and began leaking data, prompting a second suspected ransom payment. UnitedHealth disclosed $872 million in losses in April 2024, a figure that ballooned to about $2.45 billion across the nine months ending September 30, 2024. The incident has become the reference point for MFA-gap risk in critical healthcare infrastructure.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

