Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Astell&Kern to unveil the A&Ultima SP4000 digital audio player

9 May 2025

3 underrated (HBO) Max movies you should watch this weekend (May 9-11)

9 May 2025

3 great Hulu movies you need to stream this weekend (May 9 – 11)

9 May 2025
Facebook X (Twitter) Instagram
Just In
  • Astell&Kern to unveil the A&Ultima SP4000 digital audio player
  • 3 underrated (HBO) Max movies you should watch this weekend (May 9-11)
  • 3 great Hulu movies you need to stream this weekend (May 9 – 11)
  • The Galaxy S25 Edge will feature next-gen screen protection
  • Epson EcoTank ET-2980 review: a quick, low-cost all-in-one printer for families
  • US Customs and Border Protection Quietly Revokes Protections for Pregnant Women and Infants
  • Soundcore Liberty 5 review: Excellent daily driver earbuds
  • Celsius Founder Alex Mashinsky Sentenced to 12 Years in Prison
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Change Healthcare Faces Another Ransomware Threat—and It Looks Credible
News

Change Healthcare Faces Another Ransomware Threat—and It Looks Credible

News RoomBy News Room12 April 20243 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

For months, Change Healthcare has faced an immensely messy, months-long ransomware debacle that has left hundreds of pharmacies and medical practices across the United States unable to process claims. Now, thanks to an apparent dispute within the ransomware criminal ecosystem, it may have just become far messier still.

Last month, the ransomware group AlphV, which had claimed credit for encrypting Change Healthcare’s network and threatened to leak reams of the company’s sensitive health care data, received a $22 million payment—evidence, publicly captured on Bitcoin’s blockchain, that Change Healthcare had very likely caved to its tormentors’ ransom demand, though the company has yet to confirm that it paid. But in a new definition of a worst-case ransomware, a different ransomware group claims to be holding Change Healthcare’s stolen data and is demanding a payment of their own.

Since Monday, RansomHub, a relatively new ransomware group, has posted to its dark-web site that it has 4 terabytes of Change Healthcare’s stolen data, which it threatened to sell to the “highest bidder” if Change Healthcare didn’t pay an unspecified ransom. RansomHub tells WIRED it is not affiliated with AlphV and “can’t say” how much it’s demanding as a ransom payment.

RansomHub initially declined to publish or provide WIRED any sample data from that stolen trove to prove its claim. But on Friday, a representative for the group sent WIRED several screenshots of what appeared to be patient records and a data-sharing contract for United Healthcare, which owns Change Healthcare, and Emdeon, which acquired Change Healthcare in 2014 and later took its name.

While WIRED could not fully confirm RansomHub’s claims, the samples suggest that this second extortion attempt against Change Healthcare may be more than an empty threat. “For anyone doubting that we have the data, and to anyone speculating the criticality and the sensitivity of the data, the images should be enough to show the magnitude and importance of the situation and clear the unrealistic and childish theories,” the RansomHub contact tells WIRED in an email.

Change Healthcare didn’t immediately respond to WIRED’s request for comment on RansomHub’s extortion demand.

Brett Callow, a ransomware analyst with security firm Emsisoft, says he believes AlphV did not originally publish any data from the incident, and the origin of RansomHub’s data is unclear. “I obviously don’t know whether the data is real—it could have been pulled from elsewhere—but nor do I see anything that indicates it may not be authentic,” he says of the data shared by RansomHub.

Jon DiMaggio, chief security strategist at threat intelligence firm Analyst1, says he believes RansomHub is “telling the truth and does have Change HealthCare’s data,” after reviewing the information sent to WIRED. While RansomHub is a new ransomware threat actor, DiMaggio says, they are quickly “gaining momentum.”

If RansomHub’s claims are real, it will mean that Change Healthcare’s already catastrophic ransomware ordeal has become a kind of cautionary tale about the dangers of trusting ransomware groups to follow through on their promises, even after a ransom is paid. In March, someone who goes by the name “notchy” posted to a Russian cybercriminal forum that AlphV had pocketed that $22 million payment and disappeared without sharing a commission with the “affiliate” hackers who typically partner with ransomware groups and often penetrate victims’ networks on their behalf.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe Legend Of Zelda: Majora’s Mask Part 11 | Super Replay
Next Article Roku closes the barn door, badly, after a half-million accounts are compromised

Related Articles

News

Astell&Kern to unveil the A&Ultima SP4000 digital audio player

9 May 2025
News

3 underrated (HBO) Max movies you should watch this weekend (May 9-11)

9 May 2025
News

3 great Hulu movies you need to stream this weekend (May 9 – 11)

9 May 2025
News

The Galaxy S25 Edge will feature next-gen screen protection

9 May 2025
News

Epson EcoTank ET-2980 review: a quick, low-cost all-in-one printer for families

9 May 2025
News

US Customs and Border Protection Quietly Revokes Protections for Pregnant Women and Infants

9 May 2025
Demo
Top Articles

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202493 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202482 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202457 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

US Customs and Border Protection Quietly Revokes Protections for Pregnant Women and Infants

News Room9 May 2025
News

Soundcore Liberty 5 review: Excellent daily driver earbuds

News Room8 May 2025
News

Celsius Founder Alex Mashinsky Sentenced to 12 Years in Prison

News Room8 May 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025118 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202493 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202482 Views
Our Picks

The Galaxy S25 Edge will feature next-gen screen protection

9 May 2025

Epson EcoTank ET-2980 review: a quick, low-cost all-in-one printer for families

9 May 2025

US Customs and Border Protection Quietly Revokes Protections for Pregnant Women and Infants

9 May 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.