Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Save 50 percent on Paramount Plus subscriptions, and get $60 off a solar-powered dash cam

    September 13, 2025

    Spotify Lossless is an inconvenient improvement

    September 13, 2025

    Apple’s Big Bet to Eliminate the iPhone’s Most Targeted Vulnerabilities

    September 13, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment
    Security

    Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment

    News RoomBy News RoomMarch 6, 20243 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    That affiliate hacker also wrote that in their penetration of Change Healthcare’s network, they had accessed the data of numerous other health care firms partnered with the company. If that claim is accurate, Recorded Future’s Smilyanets points out, it creates the additional risk that the affiliate hacker still possesses sensitive medical information. Even if Change Healthcare did pay AlphV, the hacker affiliate could still demand additional payment or leak the data independently.

    “The affiliates still have this data, and they’re mad they didn’t receive this money,” says Smilyanets. “It’s a good lesson for everyone. You cannot trust criminals; their word is worth nothing.”

    As ransomware payments go, $22 million would represent a remarkably profitable score for AlphV. Only a relatively small number of ransoms in the history of ransomware, such as the $40 million payment made by the financial firm CNA to the hackers known as Evil Corp, have been so large, says Emsisoft’s Callow. “It’s not without precedent, but it’s certainly very unusual,” he says.

    Regardless of whether Change Healthcare is confirmed to have paid that ransom, the attack shows that AlphV has pulled off a disturbing comeback: In December, it was the target of an FBI operation that seized its dark web sites and released decryption keys that foiled its attacks on hundreds of victims. Just two months later, it carried out the cyberattack that paralyzed Change Healthcare, triggering an outage whose effects on pharmacies and their patients have now stretched well beyond a week. As of last Tuesday, AlphV listed 28 companies on the dark web site it uses to extort its victims, not including Change Healthcare.

    That site has now gone offline. As of Tuesday morning, it displayed what appeared to be a law enforcement seizure notice, but security researcher Fabian Wosar points out that the notice seems to have been copied from AlphV’s last takedown. The reason for the group’s disappearance—whether due to another law enforcement operation or AlphV’s attempts to dodge its own cheated affiliates—is unclear. Ransomware trackers say AlphV has disappeared and rebranded several times before. Earlier incarnations under the name BlackCat, BlackMatter, and Darkside were all more or less the same group, security researchers note.

    In fact, the hackers working under that Darkside handle were responsible for the 2021 Colonial Pipeline ransomware attack that triggered the shutdown of gas transportation across the Eastern Seaboard of the US and resulted in a brief fuel shortage in some East Coast cities. In that case, too, the victims paid the hackers’ ransom. “It was the hardest decision I’ve made,” Colonial’s CEO Joseph Blount later told a US congressional hearing.

    Now, it seems, some of the same hackers may have forced yet another company to make that same hard decision.

    Update 3/4/2024, 1:50 pm EST: Included additional contextual details about AlphV and related ransomware attacks.

    Updated 3/5/2024, 10:30 am EST to note that AlphV’s dark web site now displays what appears to be a law enforcement takedown message.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleGoogle’s Deal With Stack Overflow Is the Latest Proof That AI Giants Will Pay for Data
    Next Article Epic says its iOS game store plans are stalled because Apple banned its developer account

    Related Posts

    Apple’s Big Bet to Eliminate the iPhone’s Most Targeted Vulnerabilities

    September 13, 2025

    Defense Department Scrambles to Pretend It’s Called the War Department

    September 12, 2025

    US Investment in Spyware Is Skyrocketing

    September 11, 2025

    Cindy Cohn Is Leaving the EFF, but Not the Fight for Digital Rights

    September 11, 2025

    Massive Leak Shows How a Chinese Company Is Exporting the Great Firewall to the World

    September 10, 2025

    ICE Has Spyware Now

    September 9, 2025
    Our Picks

    Spotify Lossless is an inconvenient improvement

    September 13, 2025

    Apple’s Big Bet to Eliminate the iPhone’s Most Targeted Vulnerabilities

    September 13, 2025

    Why Former NFL All-Pros Are Turning to Psychedelics

    September 13, 2025

    Elon Musk is trying to silence Microsoft employees who criticize Charlie Kirk

    September 12, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    News

    Tucker Carlson asks Sam Altman if an OpenAI employee was murdered ‘on your orders’

    By News RoomSeptember 12, 2025

    Carlson: “…he was definitely murdered, I think… there were signs of a struggle, of course.…

    Nvidia’s GeForce Now Update Feels Like Someone Put an RTX 5080 in My MacBook

    September 12, 2025

    Discord is distancing itself from the Charlie Kirk shooting suspect

    September 12, 2025

    A new Astro Bot-themed PS5 controller is now available for preorder

    September 12, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.