HomeNewsChange Healthcare stolen affected person information leaked by ransomware gang

Change Healthcare stolen affected person information leaked by ransomware gang

An extortion group has printed a portion of what it says are the non-public and delicate affected person information on thousands and thousands of People stolen in the course of the ransomware assault on Change Healthcare in February.

On Monday, a brand new ransomware and extortion gang that calls itself RansomHub printed a number of recordsdata on its darkish internet leak web site containing private details about sufferers throughout completely different paperwork, together with billing recordsdata, insurance coverage information and medical data.

A number of the recordsdata, which information.killnetswitch has seen, additionally include contracts and agreements between Change Healthcare and its companions.

RansomHub threatened to promote the information to the best bidder until Change Healthcare pays a ransom.

It’s the primary time that cybercriminals have printed proof that they’ve of their possession medical and affected person information from the cyberattack.

For Change Healthcare, there’s one other complication: That is the second group to demand a ransom cost to forestall the discharge of stolen affected person information in as many months.

See also  British Library confirms information stolen throughout ransomware assault

UnitedHealth Group, the guardian firm of Change Healthcare, stated there was no proof of a brand new cyber incident. “We’re working with regulation enforcement and outdoors specialists to research claims posted on-line to grasp the extent of doubtless impacted information. Our investigation stays energetic and ongoing,” stated Tyler Mason, a spokesperson for UnitedHealth Group.

What’s extra doubtless is {that a} dispute between members and associates of the ransomware gang left the stolen information in limbo and Change Healthcare uncovered to additional extortion.

A Russia-based ransomware gang known as ALPHV took credit score for the Change Healthcare information theft. Then, in early March, ALPHV out of the blue disappeared together with a $22 million ransom cost that Change Healthcare allegedly paid to forestall the general public launch of affected person information.

Now, RansomHub says “we have now the information and never ALPHV.” Wired, which first reported the second group’s extortion effort on Friday, cited RansomHub as saying it was related to the affiliate that also had the information.

See also  The risks of anthropomorphizing AI: An infosec perspective

UnitedHealth beforehand declined to say whether or not it paid the hackers’ ransom, nor did it say how a lot information was stolen within the cyberattack.

The healthcare large stated in a press release on March 27 that it obtained a dataset “secure for us to entry and analyze,” which the corporate obtained in alternate for the ransom cost, information.killnetswitch discovered from a supply with data of the continuing incident. UHG stated it was “prioritizing the overview of information that we consider would doubtless have well being data, personally identifiable data, claims and eligibility or monetary data.”

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular