osec.one case analysis cover: Change Healthcare 2024, one Citrix portal without MFA and a $22 million ransom

The largest health data breach on record in the United States didn't start with a zero-day. It started with a working username and password, typed into a Citrix remote-access portal that had no multi-factor authentication. UnitedHealth Group's chief executive said so under oath.

Change Healthcare, a UnitedHealth subsidiary since 2022, is a clearing house: it sits between pharmacies, clinics and insurers and passes claims and payments both ways, billions of them a year. When it went dark on 21 February 2024, pharmacies couldn't check insurance and medical practices stopped getting paid. The final count of people whose data was taken is 192.7 million.

Attack chain: stolen username and password, Citrix remote-access portal with no second factor on 12 February, nine days of lateral movement, data copied out between 17 and 20 February, ALPHV/BlackCat ransomware on 21 February, $22 million paid and a second demand from RansomHub in April
No exploit in the first step. A password was enough.

Step 1: a stolen login

UnitedHealth has said only that the credentials were "compromised". How they were obtained has not been confirmed by the company.

The State of Nebraska's lawsuit, filed in December 2024, goes further. It alleges the login belonged to a low-level customer support employee and had been posted in a Telegram group known for selling stolen credentials. That is an allegation in a complaint, not a finding. It does match the pattern we covered in Snowflake 2024: passwords lifted by malware, traded in bulk, and tried against any login page that will take them.

Step 2: a remote-access portal with no second factor

On February 12, criminals used compromised credentials to remotely access a Change Healthcare Citrix portal, an application used to enable remote access to desktops. The portal did not have multi-factor authentication.
— Andrew Witty, UnitedHealth Group CEO, written testimony to the House Energy and Commerce Committee, 1 May 2024

MFA on externally facing systems was company policy. Witty told senators it is "a standard across UnitedHealth". The portal that lacked it belonged to Change, which UnitedHealth had bought in 2022 and was still moving onto newer technology. So the gap wasn't a decision to skip MFA. It was one acquired system that the policy hadn't reached yet, and nobody had a list that showed it.

Senator Ron Wyden's summary at the hearing: "This hack could have been stopped with cybersecurity 101."

Step 3: nine days inside, unseen

From the Citrix session the intruder moved to other systems "in more sophisticated ways", in Witty's words, and copied data out. Change Healthcare's breach notice puts the data theft between 17 and 20 February. The amount the criminals claimed has varied between four and six terabytes.

Nobody noticed. Not the sign-in from a new place, not the movement between servers, not terabytes leaving the network. Nebraska's complaint blames "outdated and poorly segmented" systems. The first alarm was the ransomware itself.

Step 4: ransomware, and pulling the plug

On 21 February an affiliate of the ALPHV (BlackCat) ransomware group encrypted Change's systems. The company cut its data centres off from everyone else's so the malware couldn't spread to customers or the rest of UnitedHealth. That worked, and it is also what caused the national outage: a clearing house that isn't connected clears nothing.

• Pharmacies couldn't verify coverage, so patients paid cash or went without.
• Practices and hospitals couldn't submit claims. UnitedHealth advanced about $9 billion in interest-free loans to providers to keep them open.
• Core services took weeks to return and some took most of the year. Witty said the platform was rebuilt "from scratch" so nothing from the attacked environment remained.
• UnitedHealth put the cost at $872 million in the first quarter alone. HIPAA Journal's tally of its later filings is about $2.9 billion for 2024.

Step 5: the payment that bought nothing

On 1 March 2024 a bitcoin wallet tied to ALPHV received about $22 million in one transaction. Witty later confirmed the payment: "the decision to pay a ransom was mine".

What happened next is the part worth remembering:

1. Two days later the affiliate who had done the break-in, using the name "Notchy", complained on a criminal forum that ALPHV had kept the whole payment and suspended their account.
2. ALPHV put a law-enforcement seizure banner on its site and shut down. Researchers pointed out the banner was copied from an older takedown. It was an exit scam.
3. The affiliate still had the data. In April a different group, RansomHub, listed Change Healthcare and demanded payment again. No second payment has been reported.

A ransom buys a promise from the person who robbed you. Here it didn't even reach the person holding the data.

The count kept growing

• 24 October 2024: 100 million people reported to the US health department's Office for Civil Rights.
• 24 January 2025: UnitedHealth raises it to about 190 million.
• August 2025: final figure of 192.7 million, more than half the US population.
• Dozens of class actions were consolidated in federal court in Minnesota. In November 2025 a Nebraska judge let the state's case go ahead.

Controls that break each step

Find every login page you expose, then prove each one has a second factor

• The failure was an inventory failure. Keep a list of every hostname that shows a sign-in form to the internet: VPN, remote desktop, webmail, admin panels, the hosting control panel, the system you inherited with a company or a client.
• Test from outside, not from the policy document. For each one, sign in with a real account and see whether it asks for a second factor.
• osec Scan checks a host for well-known VPN, remote-access and file-transfer login pages and, when it finds one, lists that product's flaws that CISA says are being exploited. It's a first pass over hosts you'd forgotten, not a replacement for the list.
• After any acquisition or migration, the acquired systems go on the list on day one.

Assume the password is already for sale

• A password alone should never open remote access. Use phishing-resistant MFA (passkeys or security keys) where the gateway supports it, an authenticator app where it doesn't.
• Better still, take the password away. An email code, Google or Apple sign-in leaves nothing reusable to steal from a support agent's laptop.
• Alert on sign-ins from a new country, network or device for staff accounts, and limit attempts per account, not only per IP.

Make nine quiet days impossible

• A support account should reach support tools, not every server. Segment so one remote session can't walk the network.
• Watch outbound volume per server. Terabytes leaving over four days is a signal you can catch with a simple daily threshold.
• Keep sign-in and remote-access logs off the machines they describe, for at least 90 days.

Plan for the day you disconnect

• Keep backups the production network can't write to or delete, and restore from them on a schedule so you know how long it takes.
• Decide in advance who can order systems cut off and how customers are told. Change's isolation call was right and still took a sector offline.
• If you depend on one vendor for payments or claims, know your manual fallback and how many weeks of cash you'd need.
• Don't plan around paying. This case shows a payment that neither returned the data nor ended the extortion.

The lesson for a small site

You don't run a clearing house, but you have the same shape of risk: a sign-in page facing the internet, staff passwords that may already be in someone's stealer log, and one older system the rules haven't reached. The work is dull and cheap. List the login pages, put a second factor or a passwordless sign-in on each, and look at who signs in from where. Related reading: British Airways 2018, which also began at a Citrix login without MFA, and MGM and Caesars 2023, where the help desk reset MFA for the attacker.

osec Auth puts passwordless sign-in (email code, Google, Apple) on your own site or admin page, with no OAuth setup on your side. There is no password to steal, sell or reuse.

Add passwordless sign-in

Sources: TechTarget: Change Healthcare breached via Citrix portal with no MFA (Witty's written testimony, 1 May 2024); Associated Press: Change Healthcare cyberattack was due to a lack of multifactor authentication, UnitedHealth CEO says; Krebs on Security: BlackCat ransomware group implodes after apparent $22M payment by Change Healthcare; HIPAA Journal: Change Healthcare cyberattack timeline (counts, costs, loans, Nebraska lawsuit, RansomHub); Security Affairs: Change Healthcare data breach impacted 190 million people.