Change Healthcare / ALPHV - Stolen Credentials on a Citrix Portal With No MFA → Nine Days of Lateral Movement → Ransomware → A Third of US Patients Affected
On February 12, 2024 the ALPHV/BlackCat ransomware group used compromised credentials to log in to a Change Healthcare Citrix remote access portal. The portal did not have multi-factor authentication enabled. The actors moved laterally and exfiltrated data for nine days before deploying ransomware on February 21. Change Healthcare processes around 15 billion healthcare transactions a year and touches roughly one in three US patient records, so the outage did not stay technical: pharmacies could not verify coverage, providers could not submit claims or get paid, and parts of the US healthcare payment system stopped working for weeks. UnitedHealth reportedly paid approximately $22 million, and ultimately reported around 190 million individuals affected - the largest healthcare data breach in US history. The initial access was one account, on one internet-facing portal, missing one control.
UnitedHealth's chief executive confirmed to Congress that the portal lacked MFA. There is no exploit in this step and no sophistication - a valid username and password, typed into a remote access gateway exposed to the internet, and that was sufficient. Remote access portals are the most consistently targeted surface in ransomware operations precisely because they are designed for access from anywhere, so an attacker holding credentials is indistinguishable from an employee working from home. Whether the credentials came from an infostealer log, a prior breach or a purchase was not conclusively established publicly; what was established is that a second factor would have made the answer irrelevant.
Surface: A Citrix remote desktop portal, internet-facing
Missing control: Multi-factor authentication - confirmed in congressional testimony
Credential source: Not conclusively established publicly
Why it did not matter: A second factor would have made the source moot
Nine days is a long time, and it is the part of this chain that offers defenders the most. Modern ransomware operations are double-extortion: the data has to be stolen before anything is encrypted, because the stolen copy is the leverage that survives a good backup. That means there is a substantial window in which the intrusion is quiet but active - credential harvesting, network enumeration, privilege escalation, and sustained outbound transfer of large volumes of data. Every one of those is detectable. Encryption is the end of the attack, not the beginning, and an organization that only detects at the encryption stage has skipped past its entire opportunity to intervene.
Activity in that window: Lateral movement, privilege escalation, bulk data exfiltration
Why data first: Double extortion - the stolen copy is leverage a backup cannot defeat
Detection opportunity: Nine days of anomalous internal and outbound activity
Encryption: The end of the attack, not the start
Every other chain on this page measures impact in records, dollars or systems. This one is measured in whether a patient could collect a prescription. Change Healthcare sits in the middle of US healthcare payments as a clearing house, so taking it offline did not degrade one company - it interrupted a function that thousands of independent providers and pharmacies depend on and have no alternative for. Small practices went weeks without revenue, some borrowing to make payroll; pharmacies fell back to manual processes or turned patients away. This is concentration risk in its most literal form: efficiency had routed a third of a country's patient transactions through a single processor, and no participant in that system had chosen or could see that dependency.
Reach: Roughly one in three US patient records
Consequences: Coverage verification, claims submission and provider payment all stopped
Duration: Weeks of disruption, with some services degraded for months
Root structural issue: Concentration - no alternative, and no visibility into the dependency
The payment did not end it. Public reporting described an exit scam within the ALPHV operation - the affiliate who conducted the intrusion claimed the core group took the ransom and disappeared - after which the stolen data appeared again in the hands of another extortion group demanding payment a second time. Whatever the internal truth, the lesson for anyone weighing a payment decision is concrete: paying buys a promise from a criminal organization that may not control its own affiliates, and the data can be monetized more than once. UnitedHealth ultimately reported roughly 190 million affected individuals, making this the largest healthcare data breach in US history.
What followed: An apparent exit scam within ALPHV; the affiliate said it was not paid
Then: The data resurfaced under a second extortion demand
Final scale: ~190 million individuals - the largest US healthcare breach recorded
Lesson for payment decisions: A payment buys a promise, and data can be sold twice
