Current:Home > reviewsHealth care company ties Russian-linked cybercriminals to prescriptions breach -AssetLink
Health care company ties Russian-linked cybercriminals to prescriptions breach
View
Date:2025-04-17 12:03:52
A ransomware attack is disrupting pharmacies and hospitals nationwide, leaving patients with problems filling prescriptions or seeking medical treatment.
On Thursday, UnitedHealth Group accused a notorious ransomware gang known as Black Cat, or AlphV, of hacking health care payment systems across the country.
Last week, the top health insurance company disclosed that its subsidiary, Optum, was impacted by a "cybersecurity issue," leading to its digital health care payment platform, known as Change Healthcare, being knocked offline.
As a result, hospitals, pharmacies and other health care providers have either been unable to access the popular payment platform, or have purposefully shut off connections to its network to prevent the hackers from gaining further access.
UnitedHealth says that as of Monday it estimated that more than 90% of 70,000 pharmacies in the U.S. have had to change how they process electronic claims as a result of the outage.
While the company has set up a website to track the ongoing outage, reassuring customers that there are "workarounds" to ensure access to medications, the outage could last "weeks," according to a UnitedHealth executive who spoke on a conference call with cybersecurity officers, a recording of which was obtained by STAT News.
After hiring multiple outside firms, including top cybersecurity companies Mandiant and Palo Alto Networks, UnitedHealth released its conclusion that BlackCat, or AlphV, is behind the breach, a conclusion bolstered by the group itself originally claiming credit on its dark web leak site. The post has since been taken down.
"Hacked the hackers"
However, the fact that the ransomware gang may be responsible is also something of a twist.
Just a few months ago, the FBI broke into the groups' internal servers, stealing information about decryption tools for victims and seizing control of several of its websites. The U.S. government celebrated the disruption, a major operation with multiple foreign governments involved. "In disrupting the Black Cat ransomware group, the Justice Department has once again hacked the hackers," said Deputy Attorney General Lisa Monaco in a news release.
Black Cat's seeming ability to regroup and breach one of the largest health care entities in the U.S. demonstrates how challenging it is to hamper these groups long-term.
Cybercriminals frequently reassemble after experiencing setbacks, particularly when their operators are located in countries whose law enforcement agencies are lax about prosecuting their crimes.
That's especially true in Russia. While researchers have not definitively tied BlackCat to Russia or its government, they've concluded it is a Russian-speaking group. U.S. intelligence officials have spoken frequently about the Russian government's willingness to turn a blind eye to cybercrime, in exchange for the hackers' service in intelligence operations. That has been especially true during the war in Ukraine.
In addition to the health care breach, Black Cat also recently claimed to have stolen classified documents and sensitive personal data about Department of Defense employees from U.S. federal contractors.
veryGood! (7593)
Related
- Justice Department, Louisville reach deal after probe prompted by Breonna Taylor killing
- Billy Miller's Young and the Restless Costar Peter Bergman Reflects on His Heartbreaking Death
- Strongest solar flare in years could create awesome northern lights display: What to know
- Why Emily Blunt Was Asked to Wear Something More Stylish for Her Devil Wears Prada Audition
- Why members of two of EPA's influential science advisory committees were let go
- Howard Weaver, Pulitzer Prize winner with the Anchorage Daily News, dies at age 73
- Airbnb agrees to pay $621 million to settle a tax dispute in Italy
- Matthew Perry Was Reportedly Clean for 19 Months Before His Death
- South Korean president's party divided over defiant martial law speech
- After 40 witnesses and 43 days of testimony, here’s what we learned at Trump’s civil fraud trial
Ranking
- Former Syrian official arrested in California who oversaw prison charged with torture
- This week on Sunday Morning (December 17)
- Prince Harry’s phone hacking victory is a landmark in the long saga of British tabloid misconduct
- Fuming over setback to casino smoking ban, workers light up in New Jersey Statehouse meeting
- Nevada attorney general revives 2020 fake electors case
- Prince Harry Speaks Out After Momentous Win in Phone Hacking Case
- Maryland Gov. Wes Moore says Orioles lease at Camden Yards headed to a vote
- No room at the inn? As holidays approach, migrants face eviction from New York City shelters
Recommendation
Senate begins final push to expand Social Security benefits for millions of people
Mexico closes melon-packing plant implicated in cantaloupe Salmonella outbreak that killed 8 people
Derek Hough Shares Video Update on Wife Hayley Erbert After Life-Threatening Skull Surgery
Nigeria’s Supreme Court reinstates terrorism charges against separatist leader
South Korea's acting president moves to reassure allies, calm markets after Yoon impeachment
Nigeria’s Supreme Court reinstates terrorism charges against separatist leader
Chargers fire head coach Brandon Staley, GM Tom Telesco. Who is interim coach?
The EU struggles to unify around a Gaza cease-fire call but work on peace moves continues