GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Huge US healthcare provider Change Healthcare has a “cybersecurity incident” going on for 15 hours and has shut down systems. https://techcrunch.com/2024/02/21/change-healthcare-cyberattack/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

For the first 7 hours they claimed it was just a network issue. Incident tracker: https://status.changehealthcare.com/incidents/hqpjz25fn3n7

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

As spotted by @zackwhittaker, Change Healthcare outage (still ongoing) is listed as suspected nation state threat actor in their 8-K filing.

In my experience it’s extremely rare to isolate the whole production network for nation state and espionage.. I don’t know what happened to trigger that here.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

It’s over 48 hours since the Change Healthcare outage over a “cyber security issue” began.

I have heard they may have been deliberately wiped.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Reuters reports the Change Healthcare outage, which is still ongoing almost a week later, was not caused by a “nation state” as claimed by the victim - but it’s an AlphV ransomware incident. https://www.reuters.com/technology/cybersecurity/cyber-security-outage-change-healthcare-continues-sixth-straight-day-2024-02-26/

#threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

AlphV ransomware group have claimed the ongoing Change Healthcare incident which is causing problems across the US. #threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Change Healthcare incident is rumbling on. They’ve now acknowledged it is AlphV ransomware group, not a nation state as they prior claimed. https://techcrunch.com/2024/02/29/unitedhealth-change-healthcare-ransomware-alphv-blackcat-pharmacy-outages/

#threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Since the Change Healthcare ransomware incident started several weeks ago, they've had a status page saying the incident will continue for 'the next day'.

Their COO has privately briefed orgs that will be "weeks" longer.

HT @brett for link

https://www.statnews.com/2024/02/29/change-healthcare-cyber-attack-outage-will-last-for-weeks/

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

AlphV ransomware group has received a $22m ransom payment, reportedly from Change Healthcare.

Rumours are AlphV has now scammed the ransomware affiliate and Change Healthcare, by stealing the ransom and exit scamming.

Downstream hospitals say they are losing around $100m a week due to the ongoing service outage.
https://www.wired.com/story/alphv-change-healthcare-ransomware-payment/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

AlphV’s new portal now says it has been seized by law enforcement - but it’s unclear if that’s actually true or if they’ve rug pulled.

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

Some good reporting here - the NCA, who are listed on the AlphV portal as being involved in a takedown - say they were not involved in a takedown.

We’ll see what the FBI says, but it looks like AlphV may well have done rug pull aka exit scam — stole their operator and affiliate’s money and left their victims without decryption.

https://www.reuters.com/technology/cybersecurity/blackcat-ransomware-site-claims-it-was-seized-uk-law-enforcement-denies-being-2024-03-05/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

For anybody wondering on the financial impact of the ongoing Change Healthcare ransomware incident (yes, obviously there’s also a big patient impact too):

https://therecord.media/cash-flow-disruptions-hospitals-change-healthcare

The bad news is I think ransomware groups will cause much bigger problems further down the line as they’re basically teenagers with rocket launchers inside critical infrastructure, blindly firing. They know governments worldwide are impotent.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Btw if anybody is wondering how Change Healthcare got breached, I have a draft IR report for their incident as somebody put it on a public sandbox - it’s just a standard ransomware incident. EquiLend’s IOCs are also publicly uploaded, same story.

petrichor,

@GossiTheDog I would like to take a look at that report. Do you have a link? Thanks in advance!

MNM,

@GossiTheDog Can you email to me?

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

International law enforcement all deny being behind the claimed AlphV takedown. So, exit scam confirmed.

One victim org has reached out to me asking how they contact AlphV as they still need to pay as part of claiming insurance. 💀

https://therecord.media/europol-doj-nca-deny-involvement-in-alphv-blackcat-ransomware-takedown

cdlhamma,
@cdlhamma@hachyderm.io avatar

@GossiTheDog One part I haven't gotten about all this is did they actually unlock the ransomed data? Or did they take the money and run leaving it all still inaccessible? Its possible I may have missed it somewhere.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Change Heathcare ransomware incident is still going and is having profound implications for people and the healthcare industry across the US.

But for people who think this is an isolated incident, it isn’t - it’s been like this for several years where civil society is gradually being eroded by some gangs of often kids, from schools to councils to public services worldwide (except, er, Russia).

https://prospect.org/health/2024-03-11-change-unitedhealth-ransomware-pharmacies/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The White House has met with the CEO of Change Healthcare’s parent company, around the ongoing ransomware incident. https://www.reuters.com/world/us/white-house-summons-unitedhealth-ceo-over-hack-washington-post-reports-2024-03-12/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

HT to @zackwhittaker, the US department of health has opened an investigation into Change Healthcare around if data exfiltration occurred.

It’s typically very easy to find out if data exfil happened as a third party as you can see large volumes of data transfer to VPS providers or cloud storage providers in ISP logs (which are sold onwards).

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The Change Healthcare ransomware situation is still going on, almost a month later, with at least one downstream healthcare provider saying they have run out of money to pay staff. https://www.berkshireeagle.com/news/local/cyberattack-change-healthcare-united-ransomware-medical-insurance-payments-berkshire-allergy-care/article_a5547ef2-e302-11ee-9162-2b0ff10b145f.html

HT @brett

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

One of the largest nursing home operators in the U.S. has filed for bankruptcy citing the ongoing Change Healthcare ransomware incident as a cause.

They also got hit with ransomware themselves a few months prior.

https://www.reuters.com/legal/litigation/nursing-home-co-petersen-files-bankruptcy-after-cyberattacks-2024-03-21/

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

The US government are offering $10m for information on the AlphV ransomware operator who attacked Change Healthcare https://www.reuters.com/technology/cybersecurity/us-offers-10-million-bounty-info-blackcat-hackers-who-hit-unitedhealth-2024-03-27/

Worth noting that when the incident began, the company involved refused to say #ransomware and instead claimed it was a nation state attack.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Ransomhub #ransomware group are claiming AlphV stole their money for Change Healthcare (this is believed to be true btw), and the operator has given them the data. So now they’re extorting Change Healthcare again. #threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Ransomhub have provided Wired journalists with files from Change Healthcare - meaning they’re being held to ransom again. https://www.wired.com/story/change-healthcare-ransomhub-threat/

#ransomware #threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Ransomhub have dumped what they claim is some Change Healthcare sample data on their portal. Includes some patient data. #ransomware #threatintel

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Change Healthcare have told investors they have so far taken a $872 million hit in dealing with their ongoing ransomware incident in the first two months, with the cost expected to rise to between $1350m-$1600m through the calendar year.

Shareholders don't appear to care as the stock is up 5% since the update.

https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

A Congress hearing about the Change Healthcare ransomware incident happened today - but nobody from the company bothered to attend. https://therecord.media/ransomware-unitedhealth-costs-billions-still-climbing

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Markets react to UnitedHealth taking a $1600m hit for ongoing ransomware incident at Change Healthcare

gsuberland,
@gsuberland@chaos.social avatar

@GossiTheDog really puts "there's no such thing as bad publicity" in perspective. also the fact that the stock market is unhinged and completely detached from any notion of being a representation of a business' worth, finances, or operational status.

systemadminihater,

@GossiTheDog Its cool that people all over get traumatized by their compliance audits and these assholes just skate by.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Wall Street Journal has a leak from the Change Healthcare ransomware incident

  • Initial entry was via a remote access system without MFA
  • Dwell time was 9 days
  • They paid the ransom, then got held to ransom again and had data leaked anyway

https://www.wsj.com/articles/change-healthcare-hackers-broke-in-nine-days-before-ransomware-attack-7119fdc6

#threatintel #ransomware

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

UnitedHealth says Change Healthcare ransomware threat actor stole health data on ‘substantial proportion of people in America’

Change Healthcare deal with the healthcare information of around half of Americans. https://techcrunch.com/2024/04/22/unitedhealth-change-healthcare-hackers-substantial-proportion-americans/ #threatintel #ransomware

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The CEO says entry to Change Healthcare was via an unspecified Citrix vulnerability https://www.reuters.com/technology/cybersecurity/unitedhealth-hackers-took-advantage-citrix-vulnerabilty-break-ceo-says-2024-04-29/

This conflicts with a prior WSJ report saying lack of MFA. Although maybe lack of MFA on Netscaler was the vulnerability.

#threatintel #ransomware

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

TechCrunch has really good coverage: https://techcrunch.com/2024/04/30/uhg-change-healthcare-ransomware-compromised-credentials-mfa/

Change Healthcare didn’t use MFA on Citrix Netscaler. It was a bog standard ransomware incident.

One learning for the industry btw - I saw loads of threat intel channels circulating incorrect info about the incident. That’s fine, but some (eg the health info sharing authorities) reshared this wrong info.

#threatintel #ransomware

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

The CEO of UnitedHealth is due to give testimony in Washington on their Change Healthcare ransomware incident tomorrow, where he will say “Our company alone repels an attempted intrusion every 70 seconds – thwarting more than 450,000 intrusions per year”

That sound impressive, but if you own a Windows PC at home, you’re doing the same thing - it’s called the built in firewall.

Not having MFA on Citrix Netscaler is also called negligence.

#threatintel #ransomware

guitarfosec,
@guitarfosec@cyberplace.social avatar

@GossiTheDog I'm enjoying the same copy/paste update every two hours. Don't blame them, though. It can take a while to even have half an idea of what's going on.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ethstaker
  • DreamBathrooms
  • mdbf
  • InstantRegret
  • ngwrru68w68
  • magazineikmin
  • everett
  • thenastyranch
  • Youngstown
  • slotface
  • cisconetworking
  • kavyap
  • osvaldo12
  • modclub
  • megavids
  • GTA5RPClips
  • khanakhh
  • tacticalgear
  • Durango
  • rosin
  • normalnudes
  • Leos
  • provamag3
  • tester
  • cubers
  • anitta
  • JUstTest
  • lostlight
  • All magazines