UnitedHealth Group confirmed that the cyberattack on Change Healthcare led to a data breach and a ransom payment.

UnitedHealth Group has admitted to paying a ransom to a ransomware gang that targeted its subsidiary, Change Healthcare, in February. The company made the move to protect data patientafter confirming that files containing personal information were compromised in the attack. The hackers behind the attack had previously said the company paid the ransom, but the data remains in the hands of the criminals, who are threatening to leak it again.
“This attack was carried out by malicious threat actors, and we continue to work with law enforcement and several leading cybersecurity during our investigation,” UnitedHealth told CNBC. “The ransom was paid as part of the company’s commitment to do everything it can to protect patient data from disclosure.” However, the company did not disclose the amount.
See also: Change Healthcare: Ransomware attack cost $872 million
UnitedHealth said the attackers had access to records containing protected health information and personally identifiable information of patients. The records “could cover a significant percentage of people in America,” the statement said.
The company did not say how many Americans were affected, but said that reviewing the data could "take several months," and so it may take the company some time to start notifying affected individuals.
Change Healthcare is the largest payment used by doctors, healthcare providers, and pharmacies in the United States.
UnitedHealth also contracts with over 1.6 million healthcare professionals and 8,000 healthcare facilities in all 50 states. The company continues to work to mitigate the impact of the cyberattack on consumers and providers, while extending financial assistance to affected providers.
See also: RansomHub group publishes Change Healthcare data
The company also said that 22 screenshots of compromised files have been published on the dark web, but no other data.
“We know this attack has caused concern and inconvenience for consumers and providers, and we are committed to doing everything possible to help and provide support to anyone who may need it,” said UnitedHealth CEO Andrew Witty.

Was paying the ransom a good idea?
Paying the ransom is never a good idea. Companies often resort to these methods because they think they can reduce the impact of the attack, but you can never trust hackers (as happened in the case of UnitedHealth-Change Healthcare).
The first and most immediate consequence of paying a ransom is that it encourages criminals to continue their attacks. When businesses pay, attackers see that their tactics are effective and are therefore more likely to continue using ransomware as a means of extortion.
See also: Akira ransomware has compromised over 250 organizations
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Then, paying the ransom doesn't guarantee that you'll get your data back. The attackers may not give you the necessary decryption key or decryption tool, even after you've paid. Also, stolen data may be leaked whether you pay or not.
Even if you receive the decryption key, it may not work properly or be unable to restore all of data . This means you could lose important data even after you have paid the amount.
Finally, paying the ransom may you a target for future attacks. Attackers may return with more attackssince they know you are paying the ransom.
Source: www.cnbc.com
