First reportedFebruary 21, 2024
ActivityFebruary 21, 2024
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Healthcare providers and pharmacies dependent on Change Healthcare transactions
  • Patients affected by delays in claims and pharmacy services
  • UnitedHealth Group / Change Healthcare operations

Initial access

  • unknown

Impact

  • service_disruption
  • financial_loss
  • encryption
  • extortion

Attribution

unknown low confidence

Public filings describe the incident and impacts; specific actor attribution is not asserted here from the included SEC documents.

CVEs and ATT&CK

No CVE or ATT&CK association is captured in this curated record.

Mitigations

Now

  • Maintain offline/immutable backups and regularly test restoresEnables recovery without paying ransom and reduces business downtime when systems are encrypted or wiped.

Soon

  • Segment networks and restrict administrative privilegesSlows attacker movement and limits the blast radius of ransomware deployment across the enterprise.

Later

  • Harden endpoints/servers with EDR and restrict remote admin toolsImproves detection and blocking of ransomware behaviors and common lateral-movement mechanisms used to deploy payloads.

Detection ideas

Detect mass file encryption or destructive file operations

Alert on rapid renames/overwrites across many directories, creation of ransom notes, and high-entropy writes by unfamiliar processes.

Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs

Detect lateral movement and remote execution used for ransomware deployment

Look for PsExec/SMB service creation, remote scheduled tasks, or WMIC usage followed by execution of the same binary on multiple hosts.

Data sources: EDR telemetry, Windows Security Event Logs, Network flow logs

Sources