ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

UnitedHealth admits to paying a ransom to regain access to Change Healthcare's systems

U.S. healthcare services giant UnitedHealth has admitted to paying a ransom to regain access to Change Healthcare’s systems that were encrypted by the BlackCat and RansomHub ransomware groups.

 

In February, Change Healthcare suffered a significant cyber attack that affected virtually the entire healthcare system in the U.S. The BlackCat ransomware group, which claimed responsibility for the attack and reportedly extracted a £18.3 million ransom from Change, said it took 6 terabytes of data from the company’s systems, including the data of all the company’s clients.

 

While Change Healthcare did not comment on the reports of paying the ransom, earlier this month, a group of threat actors using the pseudonym "RansomHub" announced that it also stole 4 terabytes of data from the company.

 

The group said the stolen data included personally identifiable information of active US military personnel and other patients, medical records, payment information, and more.

 

The group also claimed that it stole more than 3,000 source code files for Change Healthcare’s software solutions. According to screenshots shared on X, RansomHub gave Change Healthcare a deadline of 12 days to pay a ransom, failing which the stolen data would be published.

 

In a statement shared with BleepingComputer, UnitedHealth, the parent company of Change, said it paid a ransom to stop patient data being sold to threat actors or leaked publicly.

 

“A ransom was paid as part of the company’s commitment to do all it could to protect patient data from disclosure,” UHG said.

 

“To date, the company has not seen evidence of exfiltration of materials such as doctors’ charts or full medical histories among the data,” it added.

 

The company did not specify whether the ransom was paid to BlackCat or RansomHub, or both, but according to BleepingComputer, RansomHub removed Change Healthcare from its list of victims on its data leak website.

 

UnitedHealth says it has been able to restore pharmacy services with 99% of pre-incident pharmacies able to process claims and Change’s payment processing services are at 86% of pre-incident levels. However, it may take the organisation several months to accurately identify and notify impacted customers and individuals.

 

“We know this attack has caused concern and been disruptive for consumers and providers and we are committed to doing everything possible to help and provide support to anyone who may need it,” said UnitedHealth Group CEO Andrew Witty.  


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543