Public breach analysis BA-03
Change Healthcare, 2024: a remote access portal without MFA
UnitedHealth Group's chief executive told Congress that attackers used compromised credentials on a Citrix remote access portal that did not have multi-factor authentication. What happened in the nine days before the ransomware, and which controls would have stopped or caught each step.
Analysis of a public incident, based on published reports. Assumed Breach was not involved.
- Organisation
- Change Healthcare (UnitedHealth Group)
- When
- February 2024
- Way in
- Compromised credentials on a Citrix remote access portal
- The missing control
- Multi-factor authentication on an internet-facing remote access portal
The attack path, step by step
What the published record says happened at each stage, then our reading of it: what would have stopped the step, what would have caught it in progress, and what a test would have shown first.
Step 1. First access
Step 1: Stolen credentials and a portal with no second factor
On 12 February, criminals used compromised credentials to remotely access a Change Healthcare Citrix portal, an application used to enable remote access to desktops. The portal did not have multi-factor authentication.[1]
In written answers to the Senate, UnitedHealth Group said its policies require MFA on external-facing applications, that it acquired Change Healthcare in late 2022, and that the server at issue was a legacy Change Healthcare server.[2]
Andrew Witty told senators that the server had not had MFA deployed on it before the attack.[2]
Would have stopped it
- MFA, preferably phishing-resistant, on every internet-facing remote access service, enforced at the service itself rather than assumed from policy
- An inventory of internet-facing services checked against that policy, above all after an acquisition brings in systems built to someone else's standard
Would have caught it
- Sign-in anomaly alerts on remote access portals: new locations, new devices, and logins outside a user's normal pattern
What a test would have shown
An external penetration test enumerates what is reachable from the internet and tries it. A remote access portal that accepts a password alone is exactly the kind of finding it exists to produce, and an acquisition is the moment to commission one.
Step 2. Moving inside
Step 2: Nine days between getting in and the ransomware
Once the threat actor gained access, Witty testified, they moved laterally within the systems in more sophisticated ways and exfiltrated data. Ransomware was deployed nine days later.[1]
UnitedHealth Group told the Senate in writing that the actor gained access to Change Healthcare's Active Directory server after using privilege escalation techniques.[2]
Would have stopped it
- Tiered administration, so that an account used for a remote desktop session cannot reach the directory servers, and privileged accounts that cannot be used from ordinary desktops
- Segmentation between remote access landing zones and core identity infrastructure
Would have caught it
- Alerts on privilege escalation and on any new access to directory servers. Across nine days, each of these is an event a control could be tuned to flag
What a test would have shown
This is the assumed-breach question exactly: starting from one remote desktop session, how far does a tester get, and which step raises an alert? The answer comes back as a path, not as a list of vulnerabilities.
Step 3. Acting on objectives
Step 3: Data out first, then encryption
UnitedHealth Group told the Senate that between 17 and 20 February 2024 the threat actor exfiltrated protected health information from Change Healthcare's systems.[2]
On the morning of 21 February, a cybercriminal calling themselves ALPHV or BlackCat deployed a ransomware attack.[1]
The ransomware infected Change Healthcare's Windows and ESXi systems.[2]
Not knowing the entry point at the time, UnitedHealth Group immediately severed connectivity with Change's data centres.[1]
A joint CISA, FBI and HHS advisory, revised in February 2024, reported that of the nearly 70 victims ALPHV had leaked since mid-December 2023, healthcare was the most commonly victimised sector.[4]
Would have stopped it
- Egress controls on servers that hold health data, so a bulk transfer has nowhere to go
- Hypervisor management separated from the Windows domain, with its own credentials, so one domain compromise does not reach the virtualisation layer
Would have caught it
- Alerts on unusual outbound volume from systems holding patient data. Here the data left days before the encryption began
What a test would have shown
A red team exercise with an agreed exfiltration objective shows, safely, whether a large transfer leaves unnoticed, before a real one does.
What the organisation said it did next
- Witty testified that, as chief executive, the decision to pay a ransom was his. UnitedHealth Group later confirmed in writing that it paid the demanded $22 million in Bitcoin.[2]
- UnitedHealth Group said 22 screenshots, allegedly from exfiltrated files and some containing health and personal information, were posted on the dark web for about a week.[2]
- The team replaced thousands of laptops, rotated credentials, and rebuilt Change Healthcare's data centre network and core services.[1]
- Witty told senators that, as of the hearing on 1 May 2024, all external-facing systems across UnitedHealth Group had multi-factor authentication enabled.[2]
- UnitedHealth Group's annual report for 2024 put direct response costs at $2.2 billion and estimated the number of individuals affected at approximately 190 million.[3]
What the record does not say
Left out on purpose, because no primary source used here supports it.
- The testimony says the credentials were compromised. It does not say how they were obtained, and it cites no Citrix vulnerability.[1]
- UnitedHealth Group names ALPHV/BlackCat but does not name the affiliate it worked with.
- No official source used here says that paying the ransom guaranteed the data would be deleted or not published.
- Later totals for the number of people affected have been reported. Only the annual report figure could be checked against a primary source for this page.
Sources
Primary and authoritative sources only: company filings and statements, congressional testimony, government advisories and review boards, and published threat intelligence. Checked against the source text on 1 October 2026.
- [1]Testimony before the House Energy and Commerce Subcommittee on Oversight and Investigations
UnitedHealth Group (Andrew Witty). Congressional testimony, 1 May 2024.
- [2]Hacking America's Health Care (S. Hrg. 118-785): hearing transcript and written responses
US Senate Committee on Finance. Congressional testimony, Hearing of 1 May 2024.
- [3]Form 10-K for fiscal year 2024
UnitedHealth Group. SEC filing, Fiscal year ended 31 December 2024.
- [4]#StopRansomware: ALPHV Blackcat (AA23-353A)
CISA, FBI and HHS. Government advisory, 19 December 2023, revised 27 February 2024.
Analysis of a public incident, based on published reports. Assumed Breach was not involved.
Find your version of this path before someone else does
An assumed-breach test starts where these incidents did, inside, and shows how far one foothold reaches in your environment and which step anyone notices.
Related services: Internal & External Penetration Testing, Red Team Operations, Incident Response