Risk register · entry
Q3 · EngineeredChange Healthcare ransomware
One server without MFA froze billing for half of US healthcare.
Tightly coupled systems where one small fault cascades and takes down the whole machine.
Why this quadrant
One remote-access account had no multi-factor authentication, which is as small as a gap gets. It reached the billing system for a third of American patient records. The fraud came afterwards and twice: ALPHV took the 22 million dollar ransom and cut out the affiliate who did the work, and RansomHub then extorted the same data again.
The record
- Initial intrusion date: February 12, 2024, via a Citrix portal without MFAcertain
- Breach detected / network shut down: February 21, 2024certain
- Ransom paid: approximately $22 million, March 3, 2024certain
- RansomHub second extortion attempt: April 15, 2024likely
- Individuals notified: ~100 million (Oct 2024) growing to ~190 million (Jan 2025) and ~192.7 million (Jul 2025)certain
- Total 2024 UnitedHealth cost from the attack: approximately $2.87 billionlikely
- Attackers attributed to ALPHV/BlackCat, later RansomHubcertain
- Comparison: prior largest healthcare breach, Anthem 2015, 78.8 million recordscertain
Sources
The newsletter
One risk story a week, taken apart the way this one was: what was known, what was ignored, and which quadrant it really belonged to.
No spam, one email a week.