Summary
- Environment: Change Healthcare Citrix remote access, claims clearinghouse, pharmacy transactions, and provider payments
- Operational impact: Nationwide disruption to pharmacy claims, medical claims, and provider payments, followed by a months-long restoration and data review
- Financial impact: $3.090 billion in UnitedHealth-reported 2024 pre-tax cyberattack impacts
- Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.
What happened
On February 12, 2024, criminals used compromised credentials to enter a Change Healthcare Citrix portal used for remote desktop access. The portal did not have multi-factor authentication. The intruders then moved laterally through the environment and exfiltrated data. [2]
Nine days later, an actor identifying itself as ALPHV/BlackCat deployed ransomware and encrypted Change Healthcare systems. UnitedHealth Group disconnected affected systems to contain the attack, interrupting infrastructure used to move prescriptions, medical claims, and payments among pharmacies, providers, and health plans. [2][4]
UnitedHealth CEO Andrew Witty later testified that he authorized a ransom payment. The reviewed testimony confirms the payment but does not state its amount, so this article does not repeat an amount reported by secondary sources. [2]
Impact
- Pharmacies and providers encountered failures or delays in pharmacy claims, medical claims, and electronic payments. Some pharmacists submitted claims manually, while some medical practices faced cash-flow pressure as reimbursements stalled. [2][4]
- UnitedHealth’s preliminary sampling found files containing protected health information or personally identifiable information that could concern a substantial proportion of people in the United States. The April update did not provide a final affected-person count. [3]
- UnitedHealth reported that 22 screenshots allegedly taken from exfiltrated files appeared on the dark web for about one week; some included PHI or PII. It said at that time that it had not seen evidence that full medical histories or doctors’ charts were exfiltrated. [3]
- For 2024, UnitedHealth reported $2.223 billion in direct response costs and $867 million in reduced revenue from business disruption, producing $3.090 billion in total pre-tax cyberattack impacts. [1]
Timeline
Initial access
Compromised credentials were used to access a Citrix remote-access portal that did not have multi-factor authentication. The intruders subsequently moved laterally and exfiltrated data.
[2]Ransomware deployed
ALPHV/BlackCat deployed ransomware and encrypted systems. Change Healthcare disconnected affected systems and began containment and restoration work.
[2]Restoration plan published
UnitedHealth’s restoration update said major pharmacy systems were functioning again and set target dates for electronic payments and medical-claims connectivity.
[4]Data and service update
UnitedHealth’s data and restoration update reported preliminary PHI and PII findings. It also said pharmacy and claims processing were near normal, payment processing had reached about 86% of its pre-incident level, and approximately 80% of major-platform functionality had been restored.
[3]Full-year financial impact reported
UnitedHealth’s 2024 results quantified $3.090 billion in total pre-tax cyberattack impacts for the year.
[1]Briefing updated
This briefing was last reviewed and updated on September 19, 2026.
Threat Group & Attack Vector
The initial access path combined compromised credentials with an externally accessible Citrix portal that lacked multi-factor authentication. That sequence is narrower than saying the attackers bypassed MFA: the reviewed testimony says MFA was absent on the portal. After entry, the intruders moved laterally, removed data, and later deployed ransomware. [2]
Actors
- ALPHV/BlackCat — UnitedHealth’s CEO identified the ransomware actor by both names in sworn congressional testimony. [2]
TTPs
- T1078 — Valid Accounts — compromised credentials were used for initial access. [2]
- T1133 — External Remote Services — the credentials were used against a Citrix remote-access portal. [2]
Response
UnitedHealth said it disconnected systems after the ransomware deployment and contacted the FBI within hours. It created temporary, interest-free funding programs for providers whose cash flow was interrupted, temporarily relaxed some utilization controls, and published staged restoration targets for pharmacy, payment, and medical-claims services. [2][4]
By April 22, UnitedHealth said 99% of pre-incident pharmacies could process claims, medical claims were flowing at near-normal levels, payments were at about 86% of the pre-incident level, and roughly 80% of major-platform functionality had returned. It also opened a support line and offered two years of credit monitoring and identity-theft protection while the data review continued. [3]
