MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Change Healthcare ransomware disrupted U.S. claims and payment infrastructure

On 21 February 2024, ALPHV/BlackCat deployed ransomware inside Change Healthcare after criminals had used compromised credentials to access a Citrix portal and exfiltrate data. Change Healthcare severed connectivity and shut down affected environments, making claims, pharmacy and payment services unavailable or degraded. The outage propagated across the U.S. healthcare sector, causing claims backlogs, payment delays and significant cash-flow disruption for providers. UnitedHealth later reported USD 3.09 billion in 2024 direct-response and business-disruption impacts from the cyberattack.

94

Estimated severity

94 / 100

97

Source reliability

97 / 100

Approximate Date

21/02/2024

Targeted Company

CHANGE HEALTHCARE

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

DAVITA (Payment or financial service provider)ENCOMPASS HEALTH (Payment or financial service provider)

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

$3,090M

Impact types

Service unavailabilityService degradationDownstream customer disruptionBacklog or order accumulationOperational disruption

Affected sectors

Healthcare & Public Health

Affected departments

Information Technology

Attack Profile

Attack types

RansomwareUnauthorized accessUse of stolen credentialsData exfiltration

Attributed threat actors

ALPHVBLACKCAT

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.