Breach Reference
Scan your email →
Data breach reference · February 2024

Were you affected by the Change Healthcare (UnitedHealth) — BlackCat ransomware breach?

Disclosed
Feb 21, 2024
Records affected
190,000,000
Type
Ransomware (BlackCat/ALPHV)
Sector
Healthcare / Medical Clinic

Check if your email appears in this breach.

One-click check against public breach records. No account required.

Takes 60 seconds. We never store your email address.

What happened

Largest healthcare data breach in US history. BlackCat (ALPHV) ransomware operators used stolen credentials to access Change Healthcare's Citrix remote-access service, which did not have MFA enabled. 190 million Americans had personal and healthcare data stolen. UnitedHealth paid a $22 million ransom. Total financial impact reported at $2.45 billion through Q3 2024 per UNH earnings filings.

Reported impact: $22M ransom, $2.45B+ total cost

Source: BleepingComputer / UNH 10-Q filings

Common questions about the Change Healthcare (UnitedHealth) — BlackCat ransomware breach

When did the Change Healthcare (UnitedHealth) — BlackCat ransomware breach happen?
The breach was disclosed in February 2024. Public reporting was carried by BleepingComputer / UNH 10-Q filings. The incident is categorized as: Ransomware (BlackCat/ALPHV).
How many people were affected?
Approximately 190000000 records were reported affected. Whether your specific data was among them depends on your relationship with Change Healthcare (UnitedHealth) — BlackCat ransomware during the exposure window.
How do I check if my email was in this breach?
Enter your email in the scan form above. LeakTrace runs a check against known breach records and returns the result in under a minute. No account required.
Is my data still at risk years later?
Yes. Breach data from years past continues to circulate on active infostealer channels and credential-stuffing marketplaces. The passage of time does not neutralize the exposure. Ongoing monitoring catches new exposures as they land instead of only the ones already disclosed publicly.

Other healthcare / medical clinic sector breaches