Get 40% Off
👀 👁 🧿 All eyes on Biogen, up +4,56% after posting earnings. Our AI picked it in March 2024.
Which stocks will surge next?
Unlock AI-picked Stocks

US pharmacy outage triggered by 'Blackcat' ransomware at UnitedHealth unit, sources say

Published 02/26/2024, 01:24 PM
Updated 02/26/2024, 03:32 PM

By Raphael Satter and Christopher Bing

WASHINGTON (Reuters) - Hackers working for the 'Blackcat' ransomware gang are behind the outage at UnitedHealth (NYSE:UNH)'s technology unit that has snarled prescription deliveries for six days, two people familiar with the matter told Reuters on Monday.

The problems began last week after hackers gained access to Change Healthcare (NASDAQ:CHNG)'s information technology systems and has led to disruptions at pharmacies across the United States.

Change Healthcare and UnitedHealth did not immediately respond to requests for comment. Blackcat, also known as "ALPHV," did not immediately respond when asked whether it was responsible.

Alphabet (NASDAQ:GOOGL)'s cybersecurity unit Mandiant is handling the investigation into the breach, the two people said. In a statement, Mandiant confirmed it "has been engaged in support of the incident response" but declined to comment further.

Blackcat is one of the most notorious of the internet's many ransomware gangs - groups of cybercriminals who encrypt data to hold it hostage with the aim of securing massive payouts. It has previous struck major businesses including MGM Resorts (NYSE:MGM) International and Caesars (NASDAQ:CZR) Entertainment.

In December, Blackcat was the subject of a takedown by U.S.-led international law enforcement, which seized several websites used by the group as well as hundreds of digital keys used to decrypt victims' data.

The hackers had threatened to retaliate by extorting critical infrastructure providers and hospitals.

CISA, the U.S. cyber watchdog agency, and the FBI also did not immediately respond to emails seeking comment.

One expert said the news suggested that digital disruptions, while important, could not be counted on to knock ransomware groups out for good.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

"It's inevitable that if you have a group that's making millions of bucks, they are going to attempt to make a comeback," said Brett Callow, a threat analyst at the cybersecurity firm Emsisoft.

The allegation that Blackcat was behind the hack at Change Healthcare also raised questions about parent company UnitedHealth's previous claim that it had been targeted by a "suspected nation-state associated cybersecurity threat actor."

"I am not aware of any links between ALPHV and a nation state," Callow said. "As far as I am aware they are financially motivated cybercriminals and nothing more."

Reuters has not been able to gauge the full extent of the disruption.

A number of pharmacy chains, including CVS Health (NYSE:CVS) and Walgreens, have said the outage had knock-on effects on their businesses.

The American Pharmacists Association (APhA) said on Friday many pharmacies across the nation could not transmit insurance claims for their patients following the hack.

It said pharmacies were reporting "significant backlogs of prescriptions," which they were unable to process.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.