mastodon.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
The original server operated by the Mastodon gGmbH non-profit

Administered by:

Server stats:

352K
active users

#ALPHV

0 posts0 participants0 posts today

The state of Nebraska has sued the healthtech giant "Change Healthcare" over a series of alleged security failings that resulted in a historical data breach
exposing the sensitive health information of at least 100 million Americans.

In a complaint filed this week, Nebraska’s attorney general Mike Hilgers claims #UnitedHealth-owned Change Healthcare failed to implement proper security measures,
leading to what he describes as a “historic” data breach in terms of impact and magnitude.

This comes after it was revealed in October that more than 100 million Americans had their sensitive medical data stolen during a February ransomware attack on Change Healthcare.

This data included personal information such as addresses and phone numbers, health data including diagnoses, medications, treatment plans, and financial and banking data.

Change Healthcare continues to notify affected individuals about the data breach,
and the final number is expected to be higher than 100 million.

Hilgers said in his complaint that Change Healthcare’s
“failures to implement basic security protections”
exacerbated the extent of the cyberattack,
which was attributed to the Russian-speaking #ALPHV #ransomware gang.

The complaint alleges that the healthtech giant had poorly segmented IT systems
that allowed the hackers to travel freely between servers,
and that Change Healthcare had failed to implement multi-factor authentication on its systems,
which meant they could be accessed with just a username and password.
techcrunch.com/2024/12/18/nebr

TechCrunch · Nebraska sues Change Healthcare over security failings that led to medical data breach of over 100 million Americans | TechCrunchNew details emerged about the Change Healthcare ransomware attack in Nebraska's complaint.

#UnitedHealth says #ChangeHealthcare hack affects over 100 million, the largest-ever US #healthcare data #breach
In May, CEO Andrew Witty warned during a congressional hearing that "maybe a third" of all American's health data was exposed in the attack.
Today, US Health and Human Services Office for Civil Rights data breach portal updated total number of impacted people to 100M.
#UHG attributed cyberattack to #ALPHV/#BlackCat, #Russia-based #ransomware and extortion gang
techcrunch.com/2024/10/24/unit

TechCrunch · UnitedHealth says Change Healthcare hack affects over 100 million, the largest-ever US healthcare data breach | TechCrunch
More from Zack Whittaker

Change Healthcare submitted a breach notification to #HHS on July 19. They report the number of patients affected as "500" (a marker for "We have no friggin' idea how many and we'll get back to you at some date before the end of civilization maybe.").

They didn't comply with the "no later than 60 calendar days" requirement and I'm not sure what good a "500" report does anyone.

UnitedHealth CEO admits it paid $22 million ransom to BlackCat

UnitedHealth paid a multimillion-dollar ransom to hackers who broke into one of its subsidiaries, disrupting healthcare providers across the country for months the CEO confirmed

theverge.com/2024/5/1/24146693

The Verge · UnitedHealth CEO Andrew Witty admits he paid $22 million ransom to hackersBy Gaby Del Valle

#UnitedHealth says #ChangeHealthcare hackers stole health data on ‘substantial proportion of people in America’
The health tech giant handles health data for about half of all #Americans
The admission that hackers stole Americans’ health data comes a week after a new hacking group began publishing portions of the stolen data in an effort to extort a second #ransom demand from the company. After paying $22 million to a Russia-based criminal gang called #ALPHV in March.
techcrunch.com/2024/04/22/unit

TechCrunch · UnitedHealth says Change hackers stole health data on 'substantial proportion of people in America' | TechCrunchThe health tech giant processes 15 billion health transactions a year, and handles health information for about half of all Americans.

Onapsis and Flashpoint produced a 29 report on the cyber threat landscape for SAP applications over the past 4 years. SAP is the world's largest provider of enterprise application software. The report highlights the material risk of SAP ransomware attacks and the growing maturity of cybercriminal capabilities. Their appendices at the bottom list known SAP vulnerabilities (if they're on CISA's Known Exploited Vulnerabilities (KEV) Catalog), as well as MITRE ATT&CK techniques associated with SAP exploitation, and threat actors (financially motivated and ransomware groups) targeting SAP-using organizations. 🔗 (PDF) go.onapsis.com/threat-report/c