UnitedHealth Group reported April 22 that “a substantial proportion of people in America” could have had their protected health information (PHI) or personally identifiable information (PII) exposed in the now-famous ransomware attack on Change Healthcare. SC Media has reported that Change Healthcare, which is owned by UnitedHealth Group subsidiary Optum, suffered a cyberattack on Feb. 21, leading to widespread operational disruptions at hospitals and pharmacies across the United States. The case has led to an alleged $22 million ransom payment to BlackCat/ALPHV as well as news that a second threat group, RansomHub, had leaked a portion of stolen Change Healthcare data on the dark web.In a public statement on Monday, UnitedHealth said it found 22 screenshots containing PHI and PII from exfiltrated files that were posted for about a week on the dark web by a malicious threat actor. No further publication of PHI or PII has occurred at this time, said UnitedHealth. To date, the company has not seen evidence of exfiltration of materials such as doctors’ charts or full medical histories among the data.“We know this attack has caused concern and been disruptive for consumers and providers and we are committed to doing everything possible to help and provide support to anyone who may need it,” said Andrew Witty, chief executive officer of UnitedHealth Group. UnitedHealth also said its disclosure was not an official breach notification. The company said it will reach out to stakeholders when they have sufficient information for additional notifications.“We can expect to continue to get information in dribs and drabs,” said Toby Gouker, chief security officer at First Health Advisory, and an SC Media columnist. “And Change/UnitedHealth are not to be blamed for the slowness of discovery and disclosure. It not only looks like this has turned into a double extortion, but we have heard that the malicious actors were inside of their system a week in advance of the exploitation.”Gouker explained that these malicious actors are experts at obfuscation. Once they gained access through the remote desktop application, they moved around covertly, hiding their tracks as they proceeded to escalate their privileged access to the system and drop payloads as they went, said Gouker.“Only when the time is right they launch their exploit and all hell breaks loose,” said Gouker. “It will likely be several more months before the forensics teams can uncover all they touched in this attack.”
Ransomware, Data Security, Privacy
A ‘substantial proportion’ of Americans exposed in Change Healthcare cyberattack

(Adobe Stock)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



