Ransomware gang starts leaking alleged stolen Change Healthcare data
BleepingComputer
|
Contributed by: Drex DeFord
Summary
The RansomHub extortion gang has started to release what it claims to be corporate and patient data stolen from United Health's subsidiary, Change Healthcare, escalating a complex extortion scheme following a February cyberattack. This attack, linked to the BlackCat/ALPHV ransomware group, disrupted U.S. healthcare billing services severely. Even after the BlackCat group ceased operations amid allegations of an exit scam involving a $22 million ransom from Change Healthcare, the affiliate known as "Notchy" has partnered with RansomHub to demand another ransom. Despite not confirming any ransom payment, Change Healthcare faces a renewed threat as attackers begin leaking sensitive data, including patient information, and threaten to sell it unless their demands are met within five days.