RansomHub offers access to healthcare data breach changes

April 8, 2024
1 min read

TLDR:

– RansomHub claims access to stolen Change Healthcare data in an apparent ALPHV affiliate move.
– Security researchers found a new twist in the ongoing saga of the Change HealthCare data breach.
– The RansomHub ransomware group allegedly made claims regarding data from the United Health cybersecurity incident that was part of the ALPHV ransomware group’s final breach and exit scam.

Security researchers recently found a new twist in the ongoing saga of the Change HealthCare data breach. The RansomHub ransomware group has allegedly made claims regarding data from the United Health cybersecurity incident. This incident was purportedly part of the ALPHV ransomware group’s final breach and subsequent exit scam, involving a staggering payment of $22 million. According to security researcher Dominic Alvieri, the RansomHub ransomware group asserts ownership of data, raising suspicions of either an entry scam or potential acquisition of a BlackCat affiliate to obtain the data in question. RansomHub has claimed access to 4TB of data, however, the data is yet to be verified.

The message from the threat actor is clear: they possess sensitive data previously held by ALPHV, raising concerns about the security of highly selective information belonging to Change Health clients. The list of affected partners is extensive, amplifying the gravity of the Change HealthCare data breach. Talking about what unfolded in the United Health data breach story, the threat actor said, “ALPHV stole the ransom payment (22 Million USD) that Change Healthcare and United Health paid to restore their systems and prevent the data leak. HOWEVER, we have the data and not ALPHV.”

The aftermath of the ALPHV exit scam left many unanswered questions, particularly concerning the fate of the exfiltrated data and the looming threat of further extortion attempts. Now, with RansomHub’s emergence, these questions seem to find unsettling answers as Change Healthcare faces renewed pressure. However, uncertainties persist regarding RansomHub’s identity and motives. Is it a reincarnation of ALPHV, a migration of affiliates, or a cunning ploy to coerce Change Healthcare into another payout? The ambiguity highlights the complex and evolving nature of cybersecurity threats in the healthcare sector. This is an ongoing story and The Cyber Express will be closely monitoring the situation. We’ll update this post once we have more information on the claims made by RansomHub ransomware or any official confirmation from United Health regarding the authenticity of these claims.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and