News: 1713271833

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Change Healthcare’s ransomware attack costs edge toward $1B so far

(2024/04/16)


UnitedHealth, parent company of ransomware-besieged Change Healthcare, says the total costs of tending to the February cyberattack for the first calendar quarter of 2024 currently stands at $872 million.

That's on top of the amount in advance funding and interest-free loans UnitedHealth provided to support care providers reeling from the disruption, a sum said to be north of $6 billion.

In its results for the quarter ended March 31, filed today, UnitedHealth [1]stated that the total impact on the company from the attack in Q1 was $0.74 per share, which is expected to rise to a sum between $1.15 and $1.35 per share by the end of the year.

[2]

The remediation efforts spent on the attack are ongoing, so the total costs related to business disruption and repairs are likely to exceed $1 billion over time, potentially including the [3]reported $22 million payment made to the ALPHV/BlackCat-affiliated criminals behind the attack.

[4]

[5]

It's a charge that eclipsed that of casino group MGM, which didn't pay a ransom following an attack on its systems last year, and which [6]faces recovery costs of $100 million to rebuild its systems and paying for the fallout from outages, operational disruptions, allegedly leaked data and more.

The financial results mark the first time UnitedHealth has divulged the direct and business costs of the attack, which floored hospitals and pharmacies across the US, both in terms of cashflow and their ability to provide care.

[7]

UnitedHealth reported first-quarter revenues at $7.9 billion. It made a total Q1 net loss of $1.221 billion for the quarter. It also provided an "adjusted" quarterly earnings per share figure of $6.91 that confusingly includes the $0.25 in "business disruption impacts" but excludes both the sale of its Brazil ops and the costs of its direct response to the cyberattack, which amounted to "$0.49 per share" for the quarter. Those costs are actually going to rise, with UnitedHealth estimating those "direct response" costs are going to hit shareholders to the tune of $0.85 to $0.95 per share for the full year 2024.

The company warned that, financially, the total cost of the cyberattack is estimated to be between $1.35 billion and $1.6 billion for calendar year 2024.

[8]Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

[9]US to probe Change Healthcare's data protection standards as lawsuits mount

[10]White House and lawmakers increase pressure on UnitedHealth to ease providers' pain

[11]Change Healthcare registers pulse after crippling ransomware attack

UnitedHealth's accountants will be pleased that the company share price rose 7.5 percent in premarket trading following the release of its results – a welcome boost following the heavy dip taken since the attack.

"The core story at UnitedHealth Group remains our colleagues delivering improved experiences for the people we serve and driving balanced growth even while swiftly and effectively addressing the attack on Change Healthcare," said Andrew Witty, chief executive officer at UnitedHealth Group.

Change Healthcare is still very much feeling the effects of the incident it suffered in February, in part due to the double scumbaggery of [12]ALPHV pulling an exit scam shortly after the ransom was allegedly paid.

[13]

It's believed that the affiliate or affiliates who carried out the attack on Change never received their cut of the profits, so switched allegiances to RansomHub and are [14]once again extorting Change Healthcare using the same data they stole originally. ®

Get our [15]Tech Resources



[1] https://www.unitedhealthgroup.com/content/dam/UHG/PDF/investors/2024/UNH-Q1-2024-Release.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zh6gm6JmZXS48Gx63GV2lQAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2024/03/04/alphv_ransom_payment/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zh6gm6JmZXS48Gx63GV2lQAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zh6gm6JmZXS48Gx63GV2lQAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zh6gm6JmZXS48Gx63GV2lQAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/

[9] https://www.theregister.com/2024/03/14/change_healthcare_ransomware_investigation/

[10] https://www.theregister.com/2024/03/12/white_house_pressures_unitedhealth/

[11] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/

[12] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zh6gm6JmZXS48Gx63GV2lQAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/

[15] https://whitepapers.theregister.com/



Paul Crawford

total costs of tending to the February cyberattack for the first calendar quarter of 2024 currently stands at $872 million

I do wonder how that compares to what they actually spent on security before the attack?

Anonymous Coward

My guess is that it's approximately $872M more than they previously spent on security.

Pascal Monett

I wonder just what level of security you can get for $872 million.

I'm thinking the Board might be well advised to start budgeting a few tens of millions in that direction - because otherwise, there's a good chance that they'll be budgeting another few billion in payouts in not too long.

Nobody ever lost money buying MICROS~1 /s

Anonymous Coward

Nobody ever lost money buying MICROS~1 /s

heyrick

financially, the total cost of the cyberattack is estimated to be between $shitloads and $fucktons

No, guys, financially it's the cost of poor security practice that allowed this to happen in the first place.

Rase Premiums

mikus

Their customers will be the ones to pay for their own stupidity and laziness, not them. They obviously learned nothing after the first, paid the ransom like a fine, and went back to operating poorly. Now they got got again.

Hopefully the CIO and CISO were at least fired as part of this.

JustAnotherDistro

And so the internet, designed to be a distributed communications system for resilience, has fostered the concentration of services into utility-scale companies that are massive single points of failure, only completely unregulated.

Capital work, there.

A long time ago

Version 1.0

In the years before the Internet, the first computer (the Analytical Engine, created by Charles Babbage in the 19th century) was relatively secure. Hacking one, with our current data storage levels, would probably require about 30 large trucks to carry it away. We have made so many great technological changes since then, but while computing is so much more wonderful, hacking in a few minutes has also appeared.

I'm not saying that hacking is a "feature" ... it's just a result of our technological changes, we just need to revise our technology evolution.

Only that in you which is me can hear what I'm saying.
-- Baba Ram Dass