Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsHospitals & Medical Centers

Security leaders weigh in on the recent UnitedHealth cyberattack

By Security Staff
Pharmacy with customers

Image via Unsplash

March 5, 2024

UnitedHealth Group recently announced that an associated technological unit (Change Healthcare) faced a cyberattack from the Blackcat ransomware group. The attack caused disruptions to insurance transactions and electronic pharmacy refills. As a result, the American Hospital Association has advised that healthcare entities remain vigilant and monitor for signs of risk. 

Security leaders weigh in:

Ariel Parnes, COO and Co-Founder at Mitiga:

“In the fight against cybercrime, the state holds a critical position, employing national capabilities like intelligence, law enforcement, and international collaboration to shield against digital threats. Recently, we have seen the use of offensive cyber tactics as part of the arsenal, aiming to damage criminals' cyber capabilities and prevent their criminal activities. This method was highlighted in the disruption of the BlackCat ransomware by the FBI, which unfortunately led to the group intensifying their operations, as shown in their recent attack on UnitedHealth's tech unit.

“These cybercrime groups are resilient, often lacking a central vulnerability, which allows them to swiftly recover from attacks. Despite this, the emergence of such action-reaction dynamics in cyber confrontations should not dissuade nations from utilizing their defensive capabilities. A more effective approach involves a multidimensional, international campaign. This strategy should integrate offensive cyber countermeasures with traditional tools of national power, fostering a collective defense against cyber threats. Emphasizing cooperation and comprehensive efforts, this approach is pivotal for a robust defense against the evolving landscape of cybercrime.”

Nic Finn, Senior Threat Intelligence Consultant at GuidePoint Security:

“Following December’s law enforcement disruption of their data leak site, Alphv, also known as BlackCat, has vowed increasingly aggressive actions and removed ostensible restrictions on targeting critical infrastructure and healthcare.

“While Alphv may have notionally prohibited targeting such organizations in the past, the group has been actively attacking healthcare organizations for a while now, with several large healthcare providers and networks impacted in 2023. Of the attacks impacting healthcare we observed in 2023, Alphv was responsible for nearly 10%, second only to LockBit.

“While we have seen several healthcare organizations impacted by Alphv in 2024, it remains to be seen whether this is an intentional increase representative of deliberate targeting or just continued operations as usual, pursuing vulnerable targets of opportunity and exploiting frequent weaknesses in health organization networks. Healthcare organizations make attractive targets for ransomware groups due to the sensitivity and value of Personal Identifiable Information and Protected Health Information, which both increase extortive leverage over victims and the value of data for sale to other actors should the victim not pay.

“More than perhaps any other group, Alphv has exhibited a particularly aggressive approach to public statements, routinely ridiculing victims and their associated incident responders and calling out alleged security shortcomings, which is likely intended as much as a coercive lever and ‘final warning’ to the victims as it is a signal to future victims of the consequences of non-compliance.”

Scott Small, Director of Cyber Threat Intelligence at Tidal Cyber:

“The BlackCat group claimed Change Healthcare as a victim, and the company confirmed that cybercriminal actors are behind a recent cybersecurity incident, changing course from a previous statement that blamed nation-state hackers for the attack.

“U.S. authorities announced they disrupted BlackCat’s operations late last year, but the group has recently returned to claiming attacks against new victims. A confirmed attack against a major healthcare organization would be the strongest indication that the ransomware group has resumed its activities.

“BlackCat was the second most active ransomware gang in terms of claimed victims last year, threatening organizations in virtually every primary sector. December’s disruption operation may have temporarily or partially changed the group’s operational ability, but defenders across the community should note a confirmed return.” 

KEYWORDS: cyberattack healthcare cybersecurity ransomware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • The capitol building from the street

    Security leaders weigh in on the White House's order regarding AI

    See More
  • Dark figure coding on computer

    Security leaders weigh in on the Trump campaign hack

    See More
  • school-books.jpg

    Security leaders weigh in on school district ransomware attack

    See More

Related Products

See More Products
  • Physical Security and Safety: A Field Guide for the Practitioner

  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Events

View AllSubmit An Event
  • July 8, 2026

    The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

    ON DEMAND: In this webinar, speakers will share key insights from the 2026 Security Maturity Benchmark Report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing