Data Breaches

Change Healthcare Ransomware Attack Impacts 100 Million People

UnitedHealth told the US health department that hackers stole the information of 100 million people in a February ransomware attack.

Healthcare data breach

Change Healthcare parent company UnitedHealth Group has revealed that the personal information of 100 million individuals was compromised in the February 2024 ransomware attack.

Disclosed on February 21, the attack resulted in widespread network disruptions that impacted over 100 Change Healthcare applications across clinical, dental, medical record, patient engagement, pharmacy, and payment services. Thousands of pharmacies and healthcare providers were affected.

The attackers used leaked credentials to access a Citrix portal account that was not protected with multi-factor authentication, and lurked in Change Healthcare’s network for nine days, moving laterally and exfiltrating data before deploying file-encrypting ransomware.

Previously, UnitedHealth said the incident might have affected the information of on- third of Americans, but an updated entry on the US Department of Health and Human Services Office for Civil Rights (OCR) website now shows that 100 million individuals were affected.

“Change Healthcare is still determining the number of individuals affected. The posting on the HHS Breach Portal will be amended if Change Healthcare updates the total number of individuals affected by this breach,” OCR notes in an updated incident FAQ.

Roughly one week after the attack, the Alphv/BlackCat ransomware gang added Change Healthcare to its Tor-based leak site. The group reportedly received a $22 million ransom payment from UnitedHealth, but the RansomHub group attempted to extort the company a second time one month later.

Advertisement. Scroll to continue reading.

In April, UnitedHealth confirmed that personally identifiable information (PII) and protected health information (PHI) was stolen in the data breach.

While it had no evidence that doctors’ charts or full medical histories were taken, the company said that names, addresses, dates of birth, phone numbers, driver’s license or state ID numbers, Social Security numbers, diagnosis and treatment information, medical record numbers, billing codes, insurance member IDs, and other types of information, was likely compromised.

UnitedHealth, which incurred over $1.1 billion in total costs from the cyberattack, started sending notification letters to the potentially affected individuals in July, offering them free identity protection services.

Related: Omni Family Health Data Breach Impacts 470,000 Individuals

Related: US Offers $10 Million for Information on BlackCat Ransomware Leaders

Related: Cerebral Informing 3.1 Million Individuals of Inadvertent Data Exposure

Related: UnitedHealth Says It Has Made Progress on Recovering From Massive Cyberattack

Related Content

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Data Breaches

The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems. 

Data Breaches

French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign...

Data Breaches

The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.

Data Breaches

Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action.

Data Breaches

The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information.

Ransomware

The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password.

Data Breaches

Hackers accessed personal information stored on certain Lansing Community College systems in February 2025.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version