Ransomware group Blackcat is behind cyberattack on UnitedHealth division, company says

Traders work at the post where UnitedHealth Group is traded on the floor of the New York Stock Exchange.Brendan McDermid | Reuters

Change Healthcare on Thursday confirmed that ransomware group Blackcat is behind the ongoing cybersecurity attack that's caused widespread disruptions to pharmacies and health systems across the U.S.

“Our experts are working to address the matter and we are working closely with law enforcement and leading third-party consultants,” Change Healthcare told CNBC in a statement Thursday. “We are actively working to understand the impact to members, patients and customers.”

The company said it's working with Mandiant, which is owned by Google, and cybersecurity software vendor Palo Alto Networks.

In a since-deleted post on the dark web, Blackcat said Wednesday that it was behind the attack on Change Healthcare's systems. The group said it managed to extract six terabytes of data, including information like medical records, insurance records and payment information.

Change's parent company, UnitedHealth Group, said it discovered that a cyber threat actor breached part of the unit's information technology network on Feb. 21, according to a filing with the Securities and Exchange Commission. UnitedHealth isolated and disconnected the impacted systems “immediately upon detection” of the threat, the filing said, but it didn't disclose the nature of the attack or exactly when it took place.

Blackcat, also called Noberus and ALPHV, steals sensitive data from institutions and threatens to publish it unless a ransom is paid, according to a December release from the U.S. Department of Justice. Blackcat has compromised computer networks across the U.S. and the globe, amounting to hundreds of millions of dollars in losses, the release said.

Change Healthcare offers tools for payment and revenue cycle management that help facilitate transactions like reimbursement payments. In 2022, it merged with the health-care provider Optum, which services more than 100 million patients in the U.S. and is owned by UnitedHealth, the country's biggest health-care company by market cap.

Brett Callow, a threat analyst at the cybersecurity company Emsisoft, said ransomware groups will often make posts like these in an effort to bring victims to the negotiating table. Callow, who specializes in ransomware, shared a screenshot of Blackcat's deleted post to the social media site X on Wednesday.

He said ransomware groups often exaggerate the amount of data they've stolen, so Blackcat's claims should be treated with skepticism. It can take weeks for an organization to determine exactly what information was stolen, he added, and ransomware groups often use the period of uncertainty to their advantage.

“Cybercriminals, they're not going to tell the truth,” Callow told CNBC in an interview.

UnitedHealth said in its filing with the SEC that it suspected a nation-state-associated actor was behind the attack, but Callow said Blackcat is a for-profit cybercrime operation. He called the discrepancy “peculiar,” but said there might be more to the breach that he doesn't know about.

Ransomware attacks can be particularly dangerous within the health-care sector, as they can cause immediate harm to patients' physical safety, said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association.

When systems go dark, diagnostic technologies like CT scanners can go offline, and ambulances carrying patients are often diverted, which can delay lifesaving care, he said.

“Change, they're a victim,” Riggi told CNBC. “Ultimately, though, this was not an attack just on them, this was an attack on the entire health-care sector.”

Change Healthcare's systems have been down for nine straight days, and it's unclear when they will come back online.

Don't miss these stories from CNBC PRO:

  • Berkshire Hathaway is one of the most overbought stocks on Wall Street. Here are the others
  • Want an Nvidia alternative? These 6 chip suppliers look set to gain big from the AI boom
  • Jefferies says buy this under-the-radar software stock with ties to Nvidia and nearly 20% upside
  • 'Opportune time to invest in real estate': Pros name 5 REITs to buy right now

OTHER NEWS

24 minutes ago

We live in Britain's worst seaside town and here's why it's awful: Locals say they have lost battle against homelessness, youths vomiting in the street and drunken fights breaking out at chucking-out time

24 minutes ago

Lady Gabriella Windsor's heartbreak: How the royal is marking wedding anniversary without her beloved husband Thomas Kingston - five years after they dazzled in glorious Windsor nuptials, writes CLAUDIA JOSEPH

24 minutes ago

Why does Meghan Markle hide her feet? Duchess of Sussex often wears clothes that are too long for her 5ft 6in frame during public appearances - but a celebrity stylist reveals the unusual reason for her fashion choice

24 minutes ago

Parliament passes various bills ahead of break for elections

24 minutes ago

Donald Trump's 'speech patterns and behaviours' present 'concerns about cognitive decline'

25 minutes ago

MK Party vows to have a successful event despite problems with access to Orlando Stadium for their manifesto launch

25 minutes ago

LTA’s decision to launch new WTA event at Queens labelled ‘unacceptable’ by MPs

25 minutes ago

Cryptosporidium scammers target outbreak victims with cases set to rise as MP warns 'heads will roll'

25 minutes ago

Eton pupils give father of stabbed footballer Kiyan Price standing ovation for powerful speech

25 minutes ago

A Would-be Assassin Stirs Europe’s Violent Ghosts

25 minutes ago

'We're living proof': Americans are being paid cash by governments to move to rural areas — is inflation relocation a cure to the cost-of-living crisis?

25 minutes ago

Yellow thunderstorm warning issued for parts of England and Wales

25 minutes ago

When is a cabin no longer a cabin? Look out, this topic’s as hot as the campfire

25 minutes ago

Ukraine asks NATO to send troops for first time since war began

25 minutes ago

College students who protested and those who didn't share in disappointment at response from schools

25 minutes ago

Vailea scores against play

25 minutes ago

ITZY Are Not Only Trendsetters But Comfy Jetsetters During Born to Be World Tour

26 minutes ago

Girls Aloud reunite for first time in 11 years on tour dedicated to late bandmate Sarah Harding

26 minutes ago

4 key strategies for homebuyers in today’s challenging market

26 minutes ago

Jeff Bezos' massive Beverly Hills compound coming together

26 minutes ago

Biden admin, TikTok ask court to fast-track pivotal ruling to decide fate of social media platform

26 minutes ago

UFL schedule for Week 8 games: Odds, times, how to stream and watch on TV

27 minutes ago

How Spirit AeroSystems fits into Boeing's rebound plan

31 minutes ago

Harry Kane fitness fears for England ahead of next month's Euro 2024 kick-off

31 minutes ago

Drivers warned they could be risking their safety by not adjusting their car seat

31 minutes ago

6 Sneaky Habits That Might Be Sabotaging Your Weight Loss Goals

31 minutes ago

Great Scott, Magpies' marathon man leads by example

31 minutes ago

Johor police station attack: No Singaporean detained, says Malaysian police chief

33 minutes ago

‘I was stuck in neutral’ – Rory McIlroy targets low round on Saturday after ‘one of those days’ at Valhalla

33 minutes ago

Panthers put away Bruins in Game 6 on Gustav Forsling's late goal

33 minutes ago

Nootbaar, Winn hit 2-run homers, Cardinals drop Red Sox below .500 with 10-6 win

33 minutes ago

Welcome to the club: You're middle class but still counting your pennies

33 minutes ago

St Tropez beach club Casa Amor to open in Dubai this year

33 minutes ago

CNBC Changemaker & AstraZeneca CFO celebrates AANHPI Heritage Month

33 minutes ago

I'm a farmer... here is what Clarkson's Farm gets WRONG and right - but my customers would never pay £40 for mushroom powder!

33 minutes ago

How Harry and Meghan were welcomed to Nigeria by a fugitive airline boss wanted in the US over $20M money laundering operation

33 minutes ago

Emma Raducanu insists she is 'lucky' to have a pushy mum and dad: Tennis ace, 21, reveals: 'Some great juniors I played with had lenient parents - and they don't play tennis any more'

33 minutes ago

Happy Mondays rockstar Shaun Ryder reveals he's ditched his wild partying and cocaine use for cycling and cosy nights at home watching Corrie

33 minutes ago

The Duchess of vintage! Meghan Markle channels her late mother-in-law Princess Diana as she recreates iconic blazer ensemble in Los Angeles

33 minutes ago

Video: Girls Aloud pay emotional tribute to the late Sarah Harding as they duet with her vocals during first reunion concert - leaving fans tearfully exclaiming they 'did her proud'

Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch