Breach 065 / 076

Change Healthcare February 2024 Data Breach

The Change Healthcare breach in February 2024 involved a ransomware attack by the BlackCat group, significantly disrupting pharmacy operations. Approximately 6TB of sensitive data, including health records, was potentially compromised. The attack exploited vulnerabilities in Citrix remote-access software, highlighting security weaknesses in multi-factor authentication.
Sector
Healthcare
Year

Executive Summary

The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source

Severity of Impact

The breach significantly impacted Change Healthcare’s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach’s financial impact is estimated at $872 million, highlighting the substantial economic consequences. source

Threat Actors

The BlackCat group, operating as a ransomware-as-a-service entity, orchestrated the attack. Additionally, after the initial incident, a new group named RansomHub reportedly formed with former affiliates of ALPHV, representing continuing threats. source

Key Implications

Direct Consequences:

  • The attack caused the non-functionality of critical services, including electronic claims submission, eligibility verification, and remittance advice. source

Collateral Consequences:

  • Resultant cash flow issues led healthcare providers to seek temporary financial assistance from UnitedHealth Group and the Centers for Medicare & Medicaid Services (CMS). source

Response and Current Status

An immediate response included shutting down systems and consulting external cybersecurity firms to handle the breach. Despite these efforts, the organization experienced prolonged partial system restoration challenges and incurred a $22 million ransom payment. Full recovery operations are ongoing. source

Lessons and Recommendations

The incident underscores the necessity for enhanced network security measures, preemptive vulnerability assessments, and comprehensive disaster recovery plans. Regular security audits and implementing resilience strategies can help safeguard against similarly sophisticated threats. source

Incident Overview

Timeline

  • February 12, 2024: The initial breach of Change Healthcare occurred when an affiliate of ALPHV, named “Notchy,” accessed the network via Citrix remote-access software with compromised credentials, lacking multi-factor authentication. This allowed the attacker to establish a foothold.

  • February 21, 2024: Ransomware was deployed, significantly disrupting pharmacy operations and leading to data exfiltration, with sensitive client data reported as compromised.

  • March 2024: Change Healthcare disclosed a financial impact of $872 million due to the breach, approximately 6TB of sensitive data was exfiltrated.

  • April 8, 2024: A new ransomware group, RansomHub, emerged from the breach exploit after former ALPHV affiliates transitioned to this group.

  • April 15, 2024: RansomHub began extorting Change Healthcare further by leaking allegedly stolen data, claiming a previous ransom transaction did not reach the intended parties.

Scope of Affected Infrastructure

Change Healthcare processes approximately 15 billion medical claims annually, comprising nearly 40% of all claims in the U.S. healthcare system. The breach affected 1.6 million health professionals, 70,000 pharmacies, and 8,000 healthcare facilities nationwide.

Key Facts and Figures

  • Financial Impact: $872 million.
  • Data Exfiltration: Approximately 6TB of data.
  • Ransom Payment: $22 million paid in response to the ransomware attack.

Public Statements and Communications

Change Healthcare issued public statements addressing the incident, underscoring the financial impact and mitigation efforts while keeping stakeholders informed.

The breach led to congressional discussions regarding cybersecurity practices in large healthcare entities. Specific repercussions or regulations were not detailed in available sources.

Information Gaps

Missing specifics regarding the exact timeline of the ransom payment and further regulatory or legal actions remain undisclosed.

Technical Root Cause Analysis

ConnectWise ScreenConnect Vulnerabilities

The Change Healthcare breach was facilitated by vulnerabilities in the ConnectWise ScreenConnect software, allowing attackers to execute remote code and bypass authentication measures.

  • Exploited Vulnerabilities:
    • CVE-2024-1708: Allowed remote code execution (RCE) with a CVSS score of 8.4.
    • CVE-2024-1709: Severe RCE vulnerability with a CVSS score of 10.0.

Attack Chain and Methodology

  1. Initial Access: Attackers achieved access via compromised credentials, possibly through phishing or leveraging unpatched vulnerabilities.
  2. Account Manipulation: Created ‘cloudadmin’ and ’test@2021’ accounts, enabling unauthorized control.
  3. Network Reconnaissance: Conducted network scans, such as pinging external addresses like google.com, to establish network presence.
  4. Data Transfer Attempts: Efforts were made to connect to transfer.sh for potential data exfiltration or malware upload.

Indicators of Compromise

  • IP Addresses:

    • 155.133.5[.]15
    • 155.133.5[.]14
    • 118.69.65[.]60
    • 118.69.65[.]61
    • 207.148.120[.]105
    • 192.210.232[.]93
    • 159.203.191[].1
  • File Artifacts:

    • User.xml located at C:\Program Files (x86)\ScreenConnect\App_Data\User.xml should be examined for unauthorized account creation, specifically in the <name> and <CreationDate> fields.

Security Control Failures

  • Multi-Factor Authentication (MFA) Bypassing: The breach exposed the absence of stringent MFA controls, allowing unauthorized access.
  • Insufficient Monitoring: The failure to detect and respond to the infiltration promptly was apparent, indicating gaps in logging and network monitoring.

Network Topology and Infrastructure

  • Interconnected Systems: The breach impacted the ability of Change Healthcare’s network to isolate systems, affecting containment efforts due to the interconnected nature of the infrastructure.

Unmet Standards and Best Practices

  • Patch Management Deficiencies: There were noted failures in promptly applying security patches for CVEs related to ConnectWise ScreenConnect, exposing the system to known vulnerabilities.

Conclusion

The breach at Change Healthcare, through exploitation of known vulnerabilities and inadequate security control implementations, highlights the pressing need for rigorous access management, regular patching, and improved logging and monitoring practices. Understanding these technical vulnerabilities and enhancing network security protocols are essential to prevent future incidents.

Attack Vector and Methodology

Initial Breach

The initial breach occurred in February 2024 through the usage of compromised credentials on Citrix remote-access software that lacked multi-factor authentication (MFA). This breach was attributed to the ransomware affiliate known as “Notchy” from the ALPHV group. The absence of robust authentication measures facilitated unauthorized access to crucial systems.

Subsequent Strategies and Techniques

After gaining initial access, the attackers utilized various post-compromise activities:

  • Lateral Movement: The attackers explored the network infrastructure by leveraging compromised credentials, facilitating further privilege escalation.
  • Data Exfiltration: Sensitive data was accessed and extracted, indicating the extent of the data breach implications.

Specific Tools and Tactics

  • Malicious Scripts and Executables:

    • disableAV.bat: Disabled antivirus defenses.
    • PsExec tools (PSEXESVC.exe, psexec.exe): Facilitated lateral movement through remote process execution.
    • smbexec.exe: Executed commands on remote systems via SMB protocols.
  • Malware Components:

    • 2JSqT5dzNXW.exe: Executed a malicious driver to disable antivirus measures.
    • amd64.exe: Used for file system encryption and halting virtual machines.

Indicators of Compromise (IoCs)

  • File Hashes:
    • disableAV.bat: 813f54d9053d91a46d9ec3381a2283f3ed8274a976e34fc795c5239fd4d01f4b
    • PSEXESVC.exe: cc14df781475ef0f3f2c441d03a622ea67cd86967526f8758ead6f45174db78e
    • 2JSqT5dzNXW.exe: d9a24f5c62928dd9f5900b4a9d8ce9e09b73509bc75537c223532ebf8c22e76d
    • aSCGa.sys: 9d3a9b9875175acfa8caabbb773e0723b83735a89969c581c0dfd846476378a5
    • amd64.exe: 7539bd88d9bb42d280673b573fc0f5783f32db559c564b95ae33d720d9034f5a

Malware Deployed

The primary malware used was the ALPHV ransomware, recognized for its ability to encrypt files and propagate across SMB hosts. The ransomware component amd64.exe was integral in conducting encryption, which led to significant operational disruptions and an estimated financial loss of $872 million due to the exfiltration of 6TB of sensitive data.

Attack Progression

The attack comprised several stages:

  1. Reconnaissance: Network exploration to identify valuable systems following initial access.
  2. Exploitation and Evasion: Security defenses were bypassed to allow further network penetration.
  3. Persistence and Control: Tools like PsExec were used to maintain access across the network.
  4. Exfiltration and Encryption: Data exfiltration preceded ransomware deployment, occurring nine days post-initial compromise.

Innovative or Unexpected Methods

The tactical use of disableAV.bat variants to disable antivirus systems showcased adaptability that is not typical of standard ransomware operations. Additionally, the customization of ransomware components underscored the sophistication of the attack strategy.

Impact Assessment

Operational Disruptions

The ransomware attack on Change Healthcare led to significant operational disruptions, particularly impacting their pharmacy operations. According to Forescout Analysis , this incident forced a shutdown of over 100 applications, affecting various services such as pharmacy, medical records, and patient engagement, resulting in delays and increased transaction error rates.

Potential Long-Term Repercussions

  • Operational Resilience: As noted by PYA Insights , the incident has prompted Change Healthcare to strengthen cybersecurity measures, which will involve longer-term investments to enhance digital defenses.
  • Regulatory Scrutiny: Increased regulatory scrutiny is expected, with potential penalties due to compliance with HIPAA Privacy and Security Rules, as indicated in the CRS Report on Change Healthcare Cyberattack .

Quantifiable Financial Losses and Compromised Data Types

  • Financial Impact: The breach resulted in financial losses, including a ransom payment of approximately $22 million, and total costs potentially exceeding $1.5 billion, linked to recovery efforts and reputational damage, as reported by Forescout Analysis .
  • Data Breach Scope: Approximately 6TB of data was exfiltrated, likely containing PHI and payment details, yet specific data types remain unspecified, as stated in PYA Insights .

Broader Socio-Economic or Industry-Wide Impacts

  • Sector Vigilance: The incident has amplified cybersecurity awareness within the healthcare industry, urging organizations to fortify their cyber defenses, highlighted by Change Healthcare Cyberattack Network Connectivity Issues .
  • Insurance and Compliance Costs: Rising concerns over such cyber threats may lead to increased insurance costs and more stringent compliance standards, as per Forescout Analysis .

Comparison to Similar Incidents in the Industry

  • Comparable Incidents: This breach is comparable to incidents like the Colonial Pipeline attack, sharing themes of operational disruption and raised questions on sectoral vulnerabilities, according to PYA Insights .

Potential Reputational Damage

  • Public Trust Concerns: Concerns over Change Healthcare’s data security could diminish trust and impact future business opportunities, as detailed in Forescout Analysis .

Known Information Gaps

  • Data Exposure Details: There is a lack of detailed information on the types of sensitive data compromised and the breach’s long-term effects on client relationships, noted in CRS Report on Change Healthcare Cyberattack .
  • Recovery Timeline: The timeline for complete recovery and system restoration is still unspecified, as referenced in PYA Insights .

Recommendations and Prevention

Implement a Robust Software Patch Management Strategy

Organizations utilizing ConnectWise ScreenConnect should implement a robust software patch management strategy to address vulnerabilities such as CVE-2024-1708 and CVE-2024-1709, which were exploited to facilitate Remote Code Execution (RCE) during the Change Healthcare breach. Prompt patch application is essential to prevent the exploitation of known security issues.

Enforce Strong Authentication Mechanisms

Implement Multi-Factor Authentication (MFA) to enhance login security across all systems. Previous unauthorized access incidents during the breach underscore the need for strengthened authentication processes, including resistance against 2-factor authentication bypass as evidenced with the ‘cloudadmin’ account.

Conduct Regular Security Audits and Vulnerability Assessments

Consistent security audits and thorough vulnerability assessments are crucial for detecting potential system exposures. These practices allow organizations to proactively remediate vulnerabilities, as demonstrated by the remediation of attack vectors similar to those utilized in the Change Healthcare incident.

Develop Incident Response and Recovery Plans

Continuously updating and testing incident response plans is imperative. These plans should delineate specific actions for cyber intrusion scenarios, which can significantly reduce downtime and operational impact, such as those affecting Change Healthcare’s pharmacy operations during the attack.

Educate Staff on Cybersecurity Awareness

Cybersecurity training focused on threat recognition, such as phishing, is vital. Boosting employee awareness of social engineering tactics can mitigate the human factors contributing to security breaches, significantly enhancing an organization’s defense posture.

Conclusion

The ransomware attack on Change Healthcare in February 2024 exposed critical vulnerabilities within healthcare network security. This incident not only disrupted pharmacy operations but also allegedly resulted in the unauthorized access to sensitive client data, highlighting the pressing need for enhanced cybersecurity frameworks within healthcare organizations.

Lessons Learned to Guide Future Resilience

Healthcare organizations must transition from a perimeter-focused security strategy to a comprehensive cybersecurity approach. Integral to this shift is fostering a culture that prioritizes cybersecurity awareness among all staff members through regular training and engagement initiatives. Prompt threat detection protocols and rapid response capabilities should also be established to minimize the impact of potential breaches. PYA

Steps for Improving Security Posture and Resilience

A multi-faceted approach is essential to bolster security posture. This includes the implementation of advanced threat detection systems, regular audits of third-party software, and the development of robust disaster recovery plans. Elevating cybersecurity to a strategic priority within the C-suite will ensure adequate funding and focus on vital security initiatives. Enhancing network defenses, employee training, and conducting regular incident response drills are key strategies in improving resilience against similar threats. CRS Reports

Given the value of data within healthcare institutions, ransomware attacks are an increasing threat. The sophistication of ransomware groups requires defenses that are capable of evolving alongside emerging threats. Future attacks may leverage artificial intelligence, enabling more complex social engineering tactics. Adaptive security measures are therefore essential. Forescout

Positive Outcomes or Improvements in Security Practices

Despite the challenges posed, there are opportunities for strengthened collaboration across the healthcare sector. Sharing threat intelligence can enhance collective defenses and lead to a greater prioritization of cybersecurity in healthcare organizations. This prioritization could result in long-term investments in protecting sensitive data and systems against rising cyber threats. AHA Advisory

Data Gaps

Key data gaps remain, including the precise number of affected individuals and the full extent of compromised data. Information regarding the specific impact on patient care and the technical measures employed to mitigate the breach and recover post-incident is also missing, highlighting areas for improvement in future reporting. PYA

This report was machine-generated using the following sources:

Invariant analysis

InvariantEffectivenessConf.Explanation
Mandatory Hardware Second FactorHighThe report states the initial breach occurred via 'compromised credentials' on Citrix remote-access software that 'lacked multi-factor authentication,' explicitly citing this MFA absence as a root security control failure. A mandatory hardware second factor would have rendered the stolen/compromised Citrix credentials insufficient for authentication, stopping the attacker's initial foothold entirely and preventing the entire subsequent attack chain (account manipulation, lateral movement, data exfiltration, ransomware deployment).
Positive Execution ControlHighAfter initial access via compromised Citrix credentials, the attackers relied on execution of unauthorized binaries: disableAV.bat to disable antivirus, PsExec/PSEXESVC.exe and smbexec.exe for lateral movement, and malware components 2JSqT5dzNXW.exe and amd64.exe to disable defenses and encrypt files (the actual ransomware deployment causing the $872M impact). An application allow-list enforced on endpoints/production systems would have blocked execution of all these non-whitelisted tools, preventing AV bypass, lateral movement via PsExec/smbexec, and the ransomware encryption itself, though it would not have stopped the initial credential-based access or the data reconnaissance/exfiltration attempts that may have used legitimate allowed tools.
Egress ControlHighThe report explicitly documents attackers attempting to connect to transfer.sh for data exfiltration/malware upload and pinging external addresses like google.com for reconnaissance, plus reliance on C2 infrastructure (multiple listed IPs) to coordinate PsExec/smbexec lateral movement and exfiltrate the 6TB of data. Egress allow-listing would have blocked the transfer.sh connection and any C2 callbacks to attacker IPs, preventing bulk exfiltration of the 6TB dataset and disrupting coordinated ransomware deployment, even though the initial Citrix compromise itself would not have been prevented.
Supply Chain AgingHighThe attack chain involved exploitation of Citrix remote-access credentials and ConnectWise ScreenConnect CVEs (CVE-2024-1708, CVE-2024-1709), plus manual deployment of custom malware and off-the-shelf tools (PsExec, smbexec, disableAV.bat, ALPHV ransomware components). None of these were introduced via an open-source software dependency import process, so a supply chain aging policy has no bearing on any step of this breach.

Scored in assets/invariants/Change_Healthcare_February_2024_final.yaml — the same rows the leaderboard counts.

Read the invariant that would have stopped this

Comments

Now playing Bandcamp