
Change Healthcare reportedly paid a ransom of £18.3 million to the ALPHV/BlackCat ransomware group to recover access to its encrypted data and systems.
Headquartered in Nashville, Tennessee, Change Healthcare is one of the most prominent solutions providers to the U.S. healthcare industry, offering revenue and payment cycle management, patient and member engagement and clinical and imaging solutions to healthcare providers.
Last month, Change Healthcare, now part of Optum Solutions following a merger, said that it experienced enterprise-wide connectivity issues due to which certain applications were not functioning. The company later said the outage occurred due to a "cyber security issue" and that operational disruption could last throughout the day.
Later, in another statement, Change said the impact of the cyber attack was restricted to its internal systems and all other systems across UnitedHealth Group, its parent company, were operational. The company did not state whether it suffered a ransomware attack or if it had uncovered the root cause of the attack.
On February 28, the infamous ALPHV/BlackCat ransomware group claimed responsibility for the cyber attack on Change Healthcare and listed it as a victim on its data leak site.
“UnitedHealth has announced that the attack is "strictly related" to Change Healthcare only and it was initially attributed to a nation state actor. Two lies in one sentence. Only after threatening them to announce it was us, they started telling a different story,” the ransomware group said.
“It is true that the attack is centred at Change Healthcare production and corporate networks, but why is the damage extreme? high? Change Healthcare production servers process extremely sensitive data to all of UnitedHealth clients that rely on Change Healthcare technology solutions. Meaning thousands of healthcare providers,insurance providers, pharmacies, etc.
“Also, being inside a production network one can imagine the amount of critical and sensitive data that can be found. We were able to exfiltrate to be exact more than 6TB of highly selective data. The data relates to all Change Health clients that have sensitive data being processed by the company,” it added.
According to the ransomware group, the list of impacted organisations
ALPHV BlackCat breached UnitedHealth’s Change Healthcare which has impacted hundreds of hospitals and pharmacies across the United States.
— Dominic Alvieri (@AlvieriD) February 28, 2024
BlackCat claims the following impacted:
- Medicare
- MetLife
- CVS Caremark
- Loomis
- HealthNet
- Teachers Health Trust@nytimes… pic.twitter.com/KSwLRLUepd
According to Wired, the Bitcoin address connected to the ransomware group received 350 bitcoins in a single transaction, or close to £18.3 million based on exchange rates at the time. However, a couple of days later, an unknown cyber criminal, claiming to be an affiliate of the BlackCat group,
#ALPHV scamming affiliates? $22M paid and withdrawn pic.twitter.com/0ocKoXNLme
— 𝕯𝖒𝖎𝖙𝖗𝖞 𝕾𝖒𝖎𝖑𝖞𝖆𝖓𝖊𝖙𝖘 (@ddd1ms) March 4, 2024
As proof, the anonymous threat actor pointed to the publicly visible £18.3 million transaction on Bitcoin’s blockchain as proof.
The UnitedHealth group, however, did not comment on whether the allegations of the ransom payment were true. “We are focused on the investigation and restoring operations at Change,” it said.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543