Skip to main content
Back to overview
High

UnitedHealth Group Announces Change Healthcare Breach Impacted 190 Million Individuals

Sorry, we couldn't find any posts.

Key points

  • Original ransomware attack occurred in February 2024.
  • Updated impact estimate of 190 million individuals announced on January 27, 2025.
  • Exposed data included health insurance information, medical records, billing details, and personal information (names, addresses, Social Security numbers, government IDs).

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jan 27, 2025
Updated
Jul 22, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

ChangehealthcareData DisclosureUnitedHealth Group Announces Change HealthcareMillion Individuals SorryPleaseOpen Server Exposes Three ConcurrentEvilginx M365 Operations SCMBANKER TargetsMexican Banking With AI-Written PowerShellHelix Group Uses Vishing andDevice Code Flow

Quick context

Questions about this signal

What happened in this signal?

Sorry, we couldn't find any posts. Please try a different search. Open Server Exposes Three Concurrent Evilginx M365 Operations SCMBANKER Targets Mexican Banking With AI-Written PowerShell Helix Group Uses Vishing and Device Code Flow to Steal SharePoint Data Forg365 PhaaS Combines AiTM and Device Code Flow to Target M365 Operation DragonReturn: DcRAT Targets India Tax Professionals Unit 42 Exposes EtherRAT: Teams Calls Deliver Blockchain-Backed RAT UNK_MassTraction Exploits Roundcube XSS to Hit US Physics Departments Fake Job Interview Phishing Hits Marketing Pros Across 30 Brand Lures 90-Domain SEO Campaign Abuses ScreenConnect to Deploy AsyncRAT Unit 42 Confirms 13,000 Malicious Phantom Squatting Sites Welcome to Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities. UnitedHealth Group has revealed that the number of individuals impacted by the Change Healthcare data breach resulting from a February 2024 ransomware attack is approximately 190 million.  The healthcare technology giant previously reported that the incident impacted roughly 100 million people , making it the biggest healthcare data breach of 2024 by far. Now, the company estimates that 190 million individuals have actually been impacted by the cyberattack. “The vast majority of those people have already been provided individual or substitute notice,” UnitedHealth told SecurityWeek in an emailed statement.  “Change Healthcare is not aware of any misuse of individuals’ information as a result of this incident and has not seen electronic medical record databases appear in the data during the analysis. Support resources and information are available at changecybersupport.com ,” the company added. The security breach occurred in February, when, according to UnitedHealth, cybercriminals used compromised credentials to enter a remote access portal that was not protected by multi-factor authentication. The attackers, affiliates of the Alphv/BlackCat ransomware group , had access to the healthcare organization’s systems for nine days — in this time frame they moved laterally and exfiltrated sensitive patient data — before deploying file-encrypting malware. Advertisement. Scroll to continue reading. UnitedHealth paid a $22 million ransom to prevent a data leak, but the BlackCat group pulled an exit scam to avoid sharing the ransom with the affiliate that conducted the attack.   This led to another major ransomware group, RansomHub, attempting to extort the healthcare giant in April and publishing some of the stolen files.  According to the most recent estimates made by Change Healthcare, the cyberattack had been expected to cause losses totaling nearly $2.9 billio n. That amount may increase in light of the new revelations.  Prior to Change Healthcare’s new impact estimation, the US Department of Health and Human Services’ Office for Civil Rights received information about more than 700 healthcare data breaches impacting roughly 186 million user records . However, with this new estimate, the total number of impacted records exceeds 275 million.  Change Healthcare told SecurityWeek that “the final number will be confirmed and filed with the Office for Civil Rights at a later date”. Related : US Offering $10 Million Reward for Information on Change Healthcare Hackers Related : Major Addiction Treatment Firm BayMark Confirms Ransomware Attack Caused Data Breach Related : Medical Billing Firm Medusind Says Data Breach Impacts 360,000 People Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

When was this signal reported?

Shadow Tier lists Jan 27, 2025 as the signal date.

Which organization is connected to this signal?

Changehealthcare is the organization connected to this public signal.

Explore Changehealthcare
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence