, , ,

United Healthcare Cyberattack – Stolen Credentials, No MFA, Massive Damages

Image Credits: Patrick Sison/AP

UnitedHealth Group (UHG) CEO Andrew Witty explained in written testimony ahead of a House subcommittee hearing on Wednesday how hackers infiltrated Change Healthcare, a U.S. health tech giant it owns. The February ransomware attack caused significant disruption across the healthcare system for months.

This is the first time the health insurance giant has revealed details about the breach. Witty stated that hackers used stolen credentials to remotely access a Change Healthcare Citrix portal, a system allowing employees to access work computers remotely. Organizations like Change rely on Citrix software for this purpose.

While Witty didn’t elaborate on how the credentials were compromised, The Wall Street Journal previously reported on the use of stolen credentials. He did highlight, however, the lack of multifactor authentication (MFA) on the portal. MFA is a security measure that requires a second code sent to an employee’s trusted device, like a phone, to prevent stolen passwords from being misused. Investigators will likely delve into why Change Healthcare didn’t have MFA set up on this system.

“After gaining access, the threat actor moved laterally within the systems using more sophisticated methods and exfiltrated data,” Witty said.

Witty explained that nine days later, on February 21st, the hackers deployed ransomware. This prompted the health giant to shut down its network to contain the breach.

Last week, UnitedHealth confirmed paying a ransom to the hackers claiming responsibility for the cyberattack and subsequent data theft of terabytes of information. RansomHub, a second hacking group, has also claimed possession of the stolen data. They posted a portion of the data on the dark web and demanded a ransom to prevent further selling the information. Earlier this month, UnitedHealth reported that the ransomware attack cost them more than $870 million in the first quarter, despite generating close to $100 billion in revenue during that period.

OmniDefend Next-Generation Healthcare Protection

12.png
On-Premise Architecture
03.png
Single Sign-On And Federation
08.png
Open Standards Protocol
11.png
Universal Database
14.png
Transaction Authorization
02.png
IAM & Role Based Access Control
06.png
Data Governance & Regulatory Compliance
10.png
Zero Trust Security
07.png
Multi-Factor Authentication
05.png
Public, Private, And Hybrid Cloud Models