HomeSecurityUnitedHealth: Change Healthcare breach was via Citrix vulnerability

UnitedHealth: Change Healthcare breach was caused by Citrix vulnerability

The ransomware gang that breached UnitedHealth subsidiary Change Healthcarein February appears to have exploited a vulnerability security in Citrix softwarethat allows employees to remotely access their desktops.

UnitedHealth Change Healthcare Citrix vulnerability

This is what UnitedHealth CEO Andrew Wittybefore the House Energy and Commerce Committee tomorrow.

On the morning of February 21, affiliates of the BlackCat ransomware gang locked down systems and demanded a ransom from the company.

See also: Citrix and Sophos affected by leap year bugs

centers data to eliminate the possibility of further infection,” the testimony says.

Hackers used compromised login credentials to gain remote access to a Change Healthcare Citrix portal that was not protected by multi-factor authentication.

The Citrix vulnerability used by the ransomware group to breach Change Healthcare has not yet been disclosed, but federal agencies have warned of security vulnerabilities in Citrix tools several times since late last year.

The CEO's hearing will focus on the impact of the cyberattack on patients and service providers .

See also: CISA to federal agencies: Fix Citrix NetScaler and Chrome zero-days immediately

UnitedHealth is working with the FBI and firms cybersecurity to investigate the breach. Security experts from Google, Microsoft, Cisco and Amazon worked with researchers from Mandiant and Palo Alto Networks to secure Change Healthcare systems after the breach.

Last week, the CEO admitted that UnitedHealth paid the hackers the ransom they demanded, although we don’t know the exact amount. The company made the move to protect data patientafter confirming that files containing personal information were compromised in the attack. The hackers behind the attack had previously said that the company paid the ransom, but the data remains in the hands of the criminals, who are threatening to leak it again.

UnitedHealth: Change Healthcare breach was caused by Citrix vulnerability
UnitedHealth: Change Healthcare breach was caused by Citrix vulnerability

It's worth noting that paying the ransom is never a good idea. Companies often resort to these methods because they think they can reduce the impact of the attack, but you can never trust hackers (as happened in the case of UnitedHealth-Change Healthcare).

See also: Citrix: Warns of Netscaler zero-day vulnerabilities

The first and most immediate consequence of paying a ransom is that it encourages criminals to continue their attacks. When businesses pay, attackers see that their tactics are effective and are therefore more likely to continue using ransomware as a means of extortion.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Then, paying the ransom doesn't guarantee that you'll get your data back. The attackers may not give you the necessary decryption key or decryption tool, even after you've paid. Also, stolen data may be leaked whether you pay or not.

Source: www.reuters.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS