• News/
  • https://www.bleepingcomputer.com/news/security/unitedhealth-subsidiary-optum-hack-linked-to-blackcat-ransomware/

UnitedHealth subsidiary Optum hack linked to BlackCat ransomware

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 27, 2024
·
Updated

A cyberattack on UnitedHealth Group subsidiary Optum that led to an ongoing outage impacting the Change Healthcare payment exchange platform was linked to the BlackCat ransomware group by sources familiar with the investigation. Change Healthcare warned customers on Wednesday that some of its services are offline because of a cybersecurity incident. One day later, UnitedHealth Group said in an SEC 8-K filing that the cyberattack was coordinated by suspected "nation-state" hackers who gained access to Change Healthcare's IT systems. The Change Healthcare shutdown has led to widespread billing outages since the platform is widely used across the U.S. healthcare system by electronic health record (EHR), payment processing, care coordination, and data analytics systems in hospitals, clinics, and pharmacies. Since then, Optum has been providing daily incident updates on a dedicated status page, warning that Change Healthcare's systems are still offline to prevent further impact and contain the breach, with the outage currently impacting most services. "We have a high-level of confidence that Optum, UnitedHealthcare and UnitedHealth Group systems have not been affected by this issue," Optum says. "We are working on multiple approaches to restore the impacted environment and will not take any shortcuts or take any additional risk as we bring our systems back online." Since the attack hit its systems, ChangeHealthcare has been conducting Zoom calls with partners in the healthcare in...

Read full article

Affected Software

1 affected component
Unknown
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cyberattack on UnitedHealth subsidiary Optum that is linked to the BlackCat ransomware group.

2

What security implications are discussed in the article?

The article highlights the ongoing outage affecting the Change Healthcare payment exchange platform due to the ransomware attack.

3

What products or software are affected by the cyberattack?

The article mentions an impact on the Change Healthcare payment exchange platform.

4

Who is behind the cyberattack on Optum?

The cyberattack on Optum has been attributed to the BlackCat ransomware group.

5

What is the current status of the incident?

The incident has led to an ongoing outage and disruptions in service for affected platforms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203