HomeSecurityUnitedHealth: 2024 data breach ultimately affected 190 million people

UnitedHealth: 2024 data breach ultimately affected 190 million people

UnitedHealth has now revealed that last year's data breach ultimately affected 190 million Americans . A ransomware attack on UnitedHealth's subsidiary, Change Healthcare , led to the theft of personal and healthcare data.

UnitedHealth data breach

However, the announcement of 190 million victims is causing concern, as it is almost double the number previously revealed.

In October 2024, UnitedHealth reported to the U.S. Department of Health and Human Services’ Office for Civil Rights that the attack affected 100 million people. However, UnitedHealth reportedly confirmed (on Friday) that the number has nearly doubled to 190 million.

See also: Mission Bank: Is RansomHub behind the data breach?

“Change Healthcare has determined that the estimated total number of people affected by the cyberattack is approximately 190 million,” UnitedHealth Group told TechCrunch.

The vast majority of these individuals have already received notice. The final number will be confirmed and filed with the Office for Civil Rights at a later date.“.

While UnitedHealth says there is no indication that the threat actors have misused the stolen data, the risk is high due to the nature and volume of the data. This stolen data includes patient health insurance information, medical records, billing and payment information, and sensitive personal data (e.g., phone numbers, addresses, and, in some cases, Social Security and ID numbers).

The ransomware attack on UnitedHealth subsidiary Change Healthcare caused the largest data breach in the U.S. healthcare sector.

Change Healthcare: Attack and data breach

In February 2024, UnitedHealth subsidiary Change Healthcare was hit by a ransomware attack that led to widespread disruption of the healthcare system across the country. As a result, doctors and pharmacies were unable to effectively serve patients.

See also: Wolf Haldenstein: Data breach affects 3.5 million people

It was later revealed that the BlackCat/ALPHV ransomware gang (specifically an affiliate of the group) was behind the attack . The attackers used stolen credentials to compromise the company’s Citrix service , which did not have multi-factor authentication enabled. After breaching the network, the hackers stole 6 TB of data and encrypted computers , causing the company to shut down its IT systems and key online platforms.

UnitedHealth: 2024 data breach ultimately affected 190 million people
UnitedHealth: 2024 data breach ultimately affected 190 million people

UnitedHealth Group confirmed that it paid a ransom to prevent hackers from releasing the stolen data and to obtain the decryption key for the systems. The ransom was reportedly $22 million.

The ransom is shared between the affiliates and the ransomware operators, but it is said that the BlackCat gang suddenly shut down, stealing all the money (exit scam). After that, the attackers (affiliates) said that they did not delete the stolen data and collaborated with a new ransomware operation (RansomHub). They started leaking some of the stolen data, demanding another payment to keep all the data from being made public.

A few days later, Change Healthcare's listing on data leak website RansomHub mysteriously disappeared, indicating that United Health likely paid the ransom a second time.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Avery: Data breach of 61,000 customers

As is obvious, a ransomware attack can cause huge problems, which is why it is essential to take protective measures:

  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using solutions email security for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Back up your data regularly
  • Stay up to date on the latest ransomware trends and tactics used by attackers

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS