UnitedHealth Group announced that the ransomware attack, which hit its subsidiary Change Healthcare in February, had an financial impact $872 million on first-quarter earnings.

However, despite the $872 million loss, revenue increased by nearly $8 billion, year-over-year.
The impact of the ransomware attack includes $593 million in costs for the immediate response to the cyberattack and $279 million due to business disruptions.
See also: Jackson County networks restored after ransomware
UnitedHealth also said the cyberattack had an impact on its stock price.
Change Healthcare is the largest payment used by doctors, healthcare providers, and pharmacies in the United States.
UnitedHealth also contracts with more than 1.6 million healthcare professionals and 8,000 healthcare in all 50 states. The company continues to work to mitigate the impact of the cyberattack on consumers and providers, while extending financial assistance to affected providers.
Double blackmail
The February attack caused UnitedHealth subsidiary Optumto shut down systems and services, causing problems across the entire U.S. healthcare system.
The attack was linked to the BlackCat/ALPHV , which claimed to have stolen 6TB of data during the breach. The ransomware gang shut down shortly after, and likely ran an exit scam by stealing a $22 million ransom paid by Change Healthcare (according to claims by affiliate Notchy, which coordinated the attack).
In mid-March, the U.S. Department of Health and Human Services also announced an investigation into whether health in the attack on Change Healthcare.
See also: Nexperia: Ransomware attack and data breach

Now, it has been reported that the extortion gang RansomHub has started leaking screenshots of documents allegedly stolen from Change Healthcare’s systems. This data comes from ALPHV affiliate Notchy, who teamed up with the RansomHub gang to extort Change Healthcare again after the previous ransoms were collected by the ALPHV gang’s administrators.
The attackers warned on Monday that Change Healthcare has five days to pay a new ransom or the stolen data will be sold
What security measures can be taken to prevent future attacks?
One of the most important security is training staff on how to recognize and avoid ransomware attacks. This can include learning how to recognize suspicious emails and phishing attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, it is important to keep security software , including antivirus and firewall programs , up-to-date . Up-to-date security systems can identify and block attacks before they cause damage.
See also: Daixin ransomware gang responsible for Omni Hotels attack
It is also essential to regularly back up important data. In the event of a ransomware attack, backups can be used to restore data without the need to pay a ransom.
Finally, using multi-factor authentication can provide an extra layer of security. This means that the user will have to provide two or more forms of proof of identity to gain access to the system, making it more difficult for attackers to gain access.
Source: www.bleepingcomputer.com
