United States
USA
On 21 February 2024, ALPHV/BlackCat deployed ransomware inside Change Healthcare after criminals had used compromised credentials to access a Citrix portal and exfiltrate data. Change Healthcare severed connectivity and shut down affected environments, making claims, pharmacy and payment services unavailable or degraded. The outage propagated across the U.S. healthcare sector, causing claims backlogs, payment delays and significant cash-flow disruption for providers. UnitedHealth later reported USD 3.09 billion in 2024 direct-response and business-disruption impacts from the cyberattack.
Estimated severity
94 / 100
Source reliability
97 / 100
Approximate Date
21/02/2024
Targeted Company
CHANGE HEALTHCARE
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
$3,090M
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone