5Q Quadrants·of·Risk

Risk register · entry

Q3 · Engineered

Change Healthcare ransomware

One server without MFA froze billing for half of US healthcare.

Tightly coupled systems where one small fault cascades and takes down the whole machine.

Quadrant
Q3 Engineered
Year
2024
Impact
190M records
Sector
Healthcare IT
Region
N. America
Category
Technological

Why this quadrant

One remote-access account had no multi-factor authentication, which is as small as a gap gets. It reached the billing system for a third of American patient records. The fraud came afterwards and twice: ALPHV took the 22 million dollar ransom and cut out the affiliate who did the work, and RansomHub then extorted the same data again.

The record

  • Initial intrusion date: February 12, 2024, via a Citrix portal without MFAcertain
  • Breach detected / network shut down: February 21, 2024certain
  • Ransom paid: approximately $22 million, March 3, 2024certain
  • RansomHub second extortion attempt: April 15, 2024likely
  • Individuals notified: ~100 million (Oct 2024) growing to ~190 million (Jan 2025) and ~192.7 million (Jul 2025)certain
  • Total 2024 UnitedHealth cost from the attack: approximately $2.87 billionlikely
  • Attackers attributed to ALPHV/BlackCat, later RansomHubcertain
  • Comparison: prior largest healthcare breach, Anthem 2015, 78.8 million recordscertain

Sources

  1. Source
  2. Source
  3. Source
  4. Source

The newsletter

One risk story a week, taken apart the way this one was: what was known, what was ignored, and which quadrant it really belonged to.

No spam, one email a week.