UnitedHealth has now revealed that last year's data breach ultimately affected 190 million Americans . A ransomware attack on UnitedHealth's subsidiary, Change Healthcare , led to the theft of personal and healthcare data.

However, the announcement of 190 million victims is causing concern, as it is almost double the number previously revealed.
In October 2024, UnitedHealth reported to the U.S. Department of Health and Human Services’ Office for Civil Rights that the attack affected 100 million people. However, UnitedHealth reportedly confirmed (on Friday) that the number has nearly doubled to 190 million.
See also: Mission Bank: Is RansomHub behind the data breach?
“Change Healthcare has determined that the estimated total number of people affected by the cyberattack is approximately 190 million,” UnitedHealth Group told TechCrunch.
“The vast majority of these individuals have already received notice. The final number will be confirmed and filed with the Office for Civil Rights at a later date.“.
While UnitedHealth says there is no indication that the threat actors have misused the stolen data, the risk is high due to the nature and volume of the data. This stolen data includes patient health insurance information, medical records, billing and payment information, and sensitive personal data (e.g., phone numbers, addresses, and, in some cases, Social Security and ID numbers).
The ransomware attack on UnitedHealth subsidiary Change Healthcare caused the largest data breach in the U.S. healthcare sector.
Change Healthcare: Attack and data breach
In February 2024, UnitedHealth subsidiary Change Healthcare was hit by a ransomware attack that led to widespread disruption of the healthcare system across the country. As a result, doctors and pharmacies were unable to effectively serve patients.
See also: Wolf Haldenstein: Data breach affects 3.5 million people
It was later revealed that the BlackCat/ALPHV ransomware gang (specifically an affiliate of the group) was behind the attack . The attackers used stolen credentials to compromise the company’s Citrix service , which did not have multi-factor authentication enabled. After breaching the network, the hackers stole 6 TB of data and encrypted computers , causing the company to shut down its IT systems and key online platforms.

UnitedHealth Group confirmed that it paid a ransom to prevent hackers from releasing the stolen data and to obtain the decryption key for the systems. The ransom was reportedly $22 million.
The ransom is shared between the affiliates and the ransomware operators, but it is said that the BlackCat gang suddenly shut down, stealing all the money (exit scam). After that, the attackers (affiliates) said that they did not delete the stolen data and collaborated with a new ransomware operation (RansomHub). They started leaking some of the stolen data, demanding another payment to keep all the data from being made public.
A few days later, Change Healthcare's listing on data leak website RansomHub mysteriously disappeared, indicating that United Health likely paid the ransom a second time.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Avery: Data breach of 61,000 customers
As is obvious, a ransomware attack can cause huge problems, which is why it is essential to take protective measures:
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source: www.bleepingcomputer.com
