---
title: "Change Healthcare / UnitedHealth Group security incident"
description: "How compromised credentials and a Citrix portal without MFA enabled the Change Healthcare ransomware attack, nationwide disruption, data exposure, and $3.09 billion impact."
incident_type: "Cybersecurity incident"
status: "active"
last_modified: "2026-09-19"
canonical_url: "https://www.ally.security/incidents/change-healthcare-unitedhealth-group-security-incident-2024"
markdown_url: "https://www.ally.security/incidents/change-healthcare-unitedhealth-group-security-incident-2024.md"
stix_url: "https://www.ally.security/incidents/change-healthcare-unitedhealth-group-security-incident-2024/stix.json"
---

# Change Healthcare / UnitedHealth Group security incident

Compromised credentials gave ALPHV/BlackCat access to a Change Healthcare Citrix portal without multi-factor authentication. Ransomware deployed nine days later disrupted pharmacy, claims, and payment services across the U.S. health system.

Last modified Sep 19, 2026 · 4 sources

## Summary

- **Environment:** Change Healthcare Citrix remote access, claims clearinghouse, pharmacy transactions, and provider payments
- **Operational impact:** Nationwide disruption to pharmacy claims, medical claims, and provider payments, followed by a months-long restoration and data review
- **Financial impact:** $3.090 billion in UnitedHealth-reported 2024 pre-tax cyberattack impacts

## What happened

On February 12, 2024, criminals used compromised credentials to enter a [Change Healthcare](https://www.changehealthcare.com/) Citrix portal used for remote desktop access. The portal did not have multi-factor authentication. The intruders then moved laterally through the environment and exfiltrated data. [2](#source-2)

Nine days later, an actor identifying itself as ALPHV/BlackCat deployed ransomware and encrypted Change Healthcare systems. [UnitedHealth Group](https://www.unitedhealthgroup.com/) disconnected affected systems to contain the attack, interrupting infrastructure used to move prescriptions, medical claims, and payments among pharmacies, providers, and health plans. [2](#source-2) [4](#source-4)

UnitedHealth CEO Andrew Witty later testified that he authorized a ransom payment. The reviewed testimony confirms the payment but does not state its amount, so this article does not repeat an amount reported by secondary sources. [2](#source-2)

## Impact

- Pharmacies and providers encountered failures or delays in pharmacy claims, medical claims, and electronic payments. Some pharmacists submitted claims manually, while some medical practices faced cash-flow pressure as reimbursements stalled. [2](#source-2) [4](#source-4)
- UnitedHealth's preliminary sampling found files containing protected health information or personally identifiable information that could concern a substantial proportion of people in the United States. The April update did not provide a final affected-person count. [3](#source-3)
- UnitedHealth reported that 22 screenshots allegedly taken from exfiltrated files appeared on the dark web for about one week; some included PHI or PII. It said at that time that it had not seen evidence that full medical histories or doctors' charts were exfiltrated. [3](#source-3)
- For 2024, UnitedHealth reported **$2.223 billion** in direct response costs and **$867 million** in reduced revenue from business disruption, producing **$3.090 billion** in total pre-tax cyberattack impacts. [1](#source-1)

## Timeline

### February 12, 2024 — Initial access

Compromised credentials were used to access a Citrix remote-access portal that did not have multi-factor authentication. The intruders subsequently moved laterally and exfiltrated data. [2](#source-2)

### February 21, 2024 — Ransomware deployed

ALPHV/BlackCat deployed ransomware and encrypted systems. Change Healthcare disconnected affected systems and began containment and restoration work. [2](#source-2)

### March 7, 2024 — Restoration plan published

UnitedHealth's [restoration update](https://www.unitedhealthgroup.com/newsroom/2024/2024-03-07-uhg-update-change-healthcare-cyberattack.html) said major pharmacy systems were functioning again and set target dates for electronic payments and medical-claims connectivity. [4](#source-4)

### April 22, 2024 — Data and service update

UnitedHealth's [data and restoration update](https://www.unitedhealthgroup.com/newsroom/2024/2024-04-22-uhg-updates-on-change-healthcare-cyberattack.html) reported preliminary PHI and PII findings. It also said pharmacy and claims processing were near normal, payment processing had reached about 86% of its pre-incident level, and approximately 80% of major-platform functionality had been restored. [3](#source-3)

### January 16, 2025 — Full-year financial impact reported

UnitedHealth's [2024 results](https://www.unitedhealthgroup.com/content/dam/UHG/PDF/investors/2024/2025-16-01-uhg-reports-fourth-quarter-results.pdf) quantified $3.090 billion in total pre-tax cyberattack impacts for the year. [1](#source-1)

### September 19, 2026 — Briefing updated

This briefing was last reviewed and updated on September 19, 2026.

## Threat Group & Attack Vector

The initial access path combined compromised credentials with an externally accessible Citrix portal that lacked multi-factor authentication. That sequence is narrower than saying the attackers bypassed MFA: the reviewed testimony says MFA was absent on the portal. After entry, the intruders moved laterally, removed data, and later deployed ransomware. [2](#source-2)

### Actors

- **ALPHV/BlackCat** — UnitedHealth's CEO identified the ransomware actor by both names in sworn congressional testimony. [2](#source-2)

### TTPs

- [T1078 — Valid Accounts](https://attack.mitre.org/techniques/T1078/) — compromised credentials were used for initial access. [2](#source-2)
- [T1133 — External Remote Services](https://attack.mitre.org/techniques/T1133/) — the credentials were used against a Citrix remote-access portal. [2](#source-2)

## Response

UnitedHealth said it disconnected systems after the ransomware deployment and contacted the FBI within hours. It created temporary, interest-free funding programs for providers whose cash flow was interrupted, temporarily relaxed some utilization controls, and published staged restoration targets for pharmacy, payment, and medical-claims services. [2](#source-2) [4](#source-4)

By April 22, UnitedHealth said 99% of pre-incident pharmacies could process claims, medical claims were flowing at near-normal levels, payments were at about 86% of the pre-incident level, and roughly 80% of major-platform functionality had returned. It also opened a support line and offered two years of credit monitoring and identity-theft protection while the data review continued. [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/change-healthcare-unitedhealth-group-security-incident-2024/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### UnitedHealth Group Reports 2024 Results

official · UnitedHealth Group · Jan 16, 2025

<https://www.unitedhealthgroup.com/content/dam/UHG/PDF/investors/2024/2025-16-01-uhg-reports-fourth-quarter-results.pdf>

<a id="source-2"></a>

### Testimony of Andrew Witty

legal · U.S. House Committee on Energy and Commerce · May 1, 2024

<https://docs.house.gov/meetings/IF/IF02/20240501/117242/HHRG-118-IF02-Wstate-WittyS-20240501-U5.pdf>

<a id="source-3"></a>

### UnitedHealth Group Updates on Change Healthcare Cyberattack

official · UnitedHealth Group · Apr 22, 2024

<https://www.unitedhealthgroup.com/newsroom/2024/2024-04-22-uhg-updates-on-change-healthcare-cyberattack.html>

<a id="source-4"></a>

### UnitedHealth Group Update on Change Healthcare Cyberattack

official · UnitedHealth Group · Mar 7, 2024

<https://www.unitedhealthgroup.com/newsroom/2024/2024-03-07-uhg-update-change-healthcare-cyberattack.html>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: ALPHV/BlackCat deployed ransomware on February 21, 2024, encrypting Change Healthcare systems and prompting the company to disconnect affected systems to contain the attack.
2. **Occurred At · 100% confidence · current**  
   Restoration update: 2024-03-07
3. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: For 2024, UnitedHealth reported $2.223 billion in direct cyberattack response costs and $867 million in reduced revenue from business disruption, for $3.090 billion in total pre-tax cyberattack impacts.
4. **Attributed To · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: ALPHV/BlackCat
5. **Began At · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: 2024-02-12
6. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth's preliminary targeted sampling found files containing protected health information or personally identifiable information that could cover a substantial proportion of people in the United States.
7. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: Criminals used compromised credentials to access a Change Healthcare Citrix remote-access portal that did not have multi-factor authentication, then moved laterally and exfiltrated data.
8. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: The reviewed source documents the change healthcare / unitedhealth group security incident involving Change Healthcare, UnitedHealth Group.
9. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth reported that 22 screenshots allegedly taken from exfiltrated files, some containing PHI and PII, were posted on the dark web for about one week.
10. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: The attack disrupted pharmacy, medical-claims, and payment systems across the U.S. health system, forcing providers and pharmacists to use workarounds and creating cash-flow pressure for care providers.
11. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth contacted the FBI within hours of the ransomware deployment and continued sharing intrusion details with law enforcement.
12. **Occurred At · 100% confidence · current**  
   Full-year financial impact reported: 2025-01-16
13. **Affected Organization · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: Change Healthcare
14. **Occurred At · 100% confidence · current**  
   Data and restoration update: 2024-04-22
15. **Used Attack Technique · 95% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: https://attack.mitre.org/techniques/T1133/
16. **Affected Organization · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth Group
17. **Occurred At · 100% confidence · current**  
   Initial access: 2024-02-12
18. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth established a call center and offered two years of credit monitoring and identity-theft protection to affected people while the data review continued.
19. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: By April 22, UnitedHealth reported that 99% of pre-incident pharmacies could process claims, medical claims were flowing at near-normal levels, payment processing was at about 86% of pre-incident levels, and roughly 80% of major-platform functionality had been restored.
20. **Occurred At · 100% confidence · current**  
   Ransomware deployment and containment: 2024-02-21
21. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth created temporary, interest-free funding programs to help providers bridge cash-flow gaps while claims and payment services were disrupted.
22. **Resulted In · 100% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: UnitedHealth Group CEO Andrew Witty testified that he made the decision to pay a ransom; the testimony did not state the amount.
23. **Used Attack Technique · 95% confidence · current**  
   Change Healthcare / UnitedHealth Group security incident: https://attack.mitre.org/techniques/T1078/

</details>
