Change Healthcare hackers broke in using stolen credentials — and no MFA, says UHG CEO

The ransomware gang that hacked into U.S. health tech giant Change Healthcare used a set of stolen credentials to remotely access the company’s systems that weren’t protected by multifactor authentication (MFA), according to the chief executive of its parent company, UnitedHealth Group (UHG).

UnitedHealth CEO Andrew Witty provided the written testimony ahead of a House subcommittee hearing on Wednesday into the February ransomware attack that caused months of disruption across the U.S. healthcare system.

This is the first time the health insurance giant has given an assessment of how hackers broke into Change Healthcare’s systems, during which massive amounts of health data were exfiltrated from its systems. UnitedHealth said last week that the hackers stole health data on a “substantial proportion of people in America.”

Change Healthcare processes health insurance and billing claims for around half of all U.S. residents.

According to Witty’s testimony, the criminal hackers “used compromised credentials to remotely access a Change Healthcare Citrix portal.” Organizations like Change use Citrix software to let employees access their work computers remotely on their internal networks.

Witty did not elaborate on how the credentials were stolen. The Wall Street Journal first reported the hacker’s use of compromised credentials last week.

However, Witty did say the portal “did not have multifactor authentication,” which is a basic security feature that prevents the misuse of stolen passwords by requiring a second code sent to an employee’s trusted device, such as their phone. It’s not known why Change did not set up multifactor authentication on this system, but this will likely become a focus for investigators trying to understand potential deficiencies in the insurer’s systems.

“Once the threat actor gained access, they moved laterally within the systems in more sophisticated ways and exfiltrated data,” said Witty.

Witty said the hackers deployed ransomware nine days later on February 21, prompting the health giant to shut down its network to contain the breach.

UnitedHealth confirmed last week that the company paid a ransom to the hackers who claimed responsibility for the cyberattack and the subsequent theft of terabytes of stolen data. The hackers, known as RansomHub, are the second gang to lay claim to the data theft after posting a portion of the stolen data to the dark web and demanding a ransom to not sell the information.

UnitedHealth earlier this month said the ransomware attack cost it more than $870 million in the first quarter, in which the company made close to $100 billion in revenue.

UnitedHealth says Change hackers stole health data on ‘substantial proportion of people in America’

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
小米12国际版在Geekbench上被发现 运行Android 12系统 thumbnail

小米12国际版在Geekbench上被发现 运行Android 12系统

根据最新出现的Geekbench跑分数据列表,小米12的全球版本可能带有一个2201123G的型号。该列表显示了一个8GB内存的版本,同样采用骁龙8代芯片组,与中国的机型类似。运行的是Android 12系统,很可能上面同样运行有MIUI。但我们不确定这是否意味着小米12会在近期开始全球销售,预计需要再等几周才能确定。小米12的全球版本在运行Geekbench 5.4.4时拿下了711的单核分数和2834的多核分数,这款机型采用6.28英寸FHD+AMOLED屏幕面板,提供120Hz刷新率,由大猩猩玻璃Victus保护,三个后置摄像头,包括一个5000万像素的主传感器,一个1300万像素的广角单元,以及一个500万像素的微距传感器。这款手机还配备了一个3200万像素的自拍相机,以及一个支持67W快速充电的4500mAh电池。
Read More
5 Things That Helped Me Survive 2 Massive Power Outages thumbnail

5 Things That Helped Me Survive 2 Massive Power Outages

Why You Can Trust CNET Our expert, award-winning staff selects the products we cover and rigorously researches and tests our top picks. If you buy through our links, we may get a commission. Reviews ethics statement My kid's frog flashlight was helpful, but a huge battery was the real lifesaver. Stephen Shankland principal writer Stephen
Read More
With Fist Bumps and Nasal Swabs, Tech Conferences Are Back thumbnail

With Fist Bumps and Nasal Swabs, Tech Conferences Are Back

The return of tech conferences began not with a bang, but a whisper. It was the first day of Code Conference, and Kara Swisher—one of the most prominent voices in technology criticism—had lost her voice. She welcomed attendees back, after a Covid hiatus, in a Marge Simpson rasp.Swisher has been hosting Code Conference, an annual…
Read More
Amazon says vaccinated warehouse workers can now work unmasked thumbnail

Amazon says vaccinated warehouse workers can now work unmasked

Amazon warehouse employees who have been vaccinated against COVID-19 no longer need to wear face masks at work, The Wall Street Journal reported. The company is rolling back a mask requirement it last put back into effect during the omicron surge in December. Last year, the mask requirement was lifted between May and August and…
Read More
Index Of News