Ransomware gang starts leaking alleged stolen Change Healthcare data

By Lawrence Abrams, Bleeping Computer

The RansomHub extortion gang has begun leaking what they claim is corporate and patient data stolen from United Health subsidiary Change Healthcare in what has been a long and convoluted extortion process for the company.

In February, Change Healthcare suffered a cyberattack that caused massive disruption to the US healthcare system, preventing pharmacies and doctors from billing or sending claims to insurance companies.

The attack was ultimately linked to the BlackCat/ALPHV ransomware operation, who later said they stole 6 TB of data during the attack.

After facing increased pressure from law enforcement, the BlackCat gang shut down their operation. This occurred amid claims they were pulling an exit scam by stealing a $22 million Change Healthcare ransom payment from the affiliate who conducted the attack.

While Change Healthcare has declined to comment on whether it has paid a ransom, the affiliate known as "Notchy" said they would extort Change Healthcare again as they still had the company's data.



Comments

Popular posts from this blog

New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

Why remote desktop tools are facing an onslaught of cyber threats