UnitedHealth CEO: 'Decision to pay ransom was mine'
- Reference: 1714506670
- News link: https://www.theregister.co.uk/2024/04/30/unitedhealth_ceo_ransom/
- Source link:
Once they were into that management system, the miscreants were able to move through the network to steal people's sensitive data and deploy extortionware.
As well as that admission, Witty is also expected to confirm making a payment to the extortionists to presumably prevent a wider leak of that info, which reportedly cost the healthcare giant [1]$22 million .
[2]
"As chief executive officer, the decision to pay a ransom was mine," as Witty put it in written testimony
[3]PDF
he will deliver to the House Energy and Commerce Committee on May 1. "This was one of the hardest decisions I've ever had to make. And I wouldn't wish it on anyone."[4]
[5]
The House committee called Witty to explain himself as it is this week [6]probing the Change Healthcare cyberattack. The US Senate Finance Committee is holding a hearing Wednesday along the same lines, and Witty will [7]testify at both inquiries.
Plus, three US Senators on Monday sent a letter
[8]PDF
to the US government's Cybersecurity and Infrastructure Security Agency (CISA) asking the infosec body to provide details about how it's helping Change Healthcare recover from the February IT breach, as well as the larger risk from ransomware.Crims spent nine days snooping around
On February 12, ALPHV ransomware affiliates gained access to the healthcare org's IT systems using "compromised credentials to remotely access a Change Healthcare Citrix portal, an application used to enable remote access to desktops," according to Witty's upcoming testimony.
"The portal did not have multi-factor authentication," Witty will testify during the House committee hearing. "Once the threat actor gained access, they moved laterally within the systems in more sophisticated ways and exfiltrated data. Ransomware was deployed nine days later."
[9]
ALPHV criminals activated its malware on February 21, "encrypting Change's systems so we could not access them," according to the written testimony.
And that's when [10]hospitals and pharmacies across the US that use Change's insurance and billing services ground to a screeching halt, preventing patients from receiving much-needed medications and medical services under their health plans.
It took weeks for UnitedHealth, which owns Change Healthcare and Optum, to begin bringing electronic prescriptions [11]back online in early March.
[12]
The healthcare giant has said the ransomware infection has cost it [13]$870 million so far, and that figure could hit $1.6 billion for the year.
More ransomware crews pile on
Upon discovering the ransomware infection, UnitedHealth "immediately severed connectivity with Change's datacenters" to prevent the malware from spreading, the testimony tells us. But by then, the crooks had already stolen a ton of protected health data and personally identifiable information covering "a [14]substantial proportion of people in America."
In addition to the ALPHV affiliate, another criminal crew RansomHub later [15]released alleged personal patient data from the break-in and also demanded a ransom.
And just last week, a third ransomware group — Medusa — claimed to have [16]cracked servers belonging to healthcare services network Northeast Ohio Neighborhood Health, and stolen almost 51GB of data.
According to SuspectFile, which [17]first reported this intrusion, many of the stolen records belong to patients associated with health insurance contracts at UnitedHealth.
UnitedHealth contacted the FBI "within hours" of the ransomware attack, according to Witty, and by the afternoon of February 21 it had a whole team of heavy-hitters working to secure the perimeter and rebuild Change's IT systems. This included incident responders from Mandiant and Palo Alto Networks, along with experts from Google, Microsoft, Cisco, Amazon, and others.
"The team replaced thousands of laptops, rotated credentials, rebuilt Change Healthcare's data center network and core services, and added new server capacity," Witty's testimony reads. "The team delivered a new technology environment in just weeks — an undertaking that would have taken many months under normal circumstances."
[18]UnitedHealth admits IT security breach could 'cover substantial proportion of people in America'
[19]Change Healthcare's ransomware attack costs edge toward $1B so far
[20]Change Healthcare faces second ransomware dilemma weeks after ALPHV attack
[21]US to probe Change Healthcare's data protection standards as lawsuits mount
Also according to Witty, this ransomware attack wasn't an isolated event. UnitedHealth wards off attempted digital break-ins every 70 seconds, "thwarting more than 450,000 intrusions per year," he claimed. It really does depend on how you measure an intrusion, attempt or otherwise.
In light of these escalating attacks targeting hospitals and other critical infrastructure, Witty says he supports [22]policy changes to mandate better cybersecurity practices among healthcare organizations.
"We support mandatory minimum security standards — developed collaboratively by the government and private sector — for the health-care industry," his testimony reads. "Importantly, these efforts must include funding and training for institutions that need help in making that transition, such as hospitals in rural communities."
UnitedHealth also supports other efforts to improve US cybersecurity including "greater notification to law enforcement and standardized and nationalized cybersecurity event reporting," Witty will tell lawmakers on Wednesday. ®
Get our [23]Tech Resources
[1] https://www.theregister.com/2024/03/04/alphv_ransom_payment/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjFp@BNmhsjJFw53lGmbUAAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://regmedia.co.uk/2024/04/30/unitedhealth_ceo_andrew_witty_testimony.pdf
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjFp@BNmhsjJFw53lGmbUAAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjFp@BNmhsjJFw53lGmbUAAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://energycommerce.house.gov/posts/chairs-rodgers-and-griffith-announce-united-health-ceo-to-testify-at-oversight-hearing-on-change-healthcare-attack
[7] https://www.finance.senate.gov/hearings/hacking-americas-health-care-assessing-the-change-healthcare-cyber-attack-and-whats-next
[8] https://regmedia.co.uk/2024/04/30/warren_cisa_letter_healthcare.pdf
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjFp@BNmhsjJFw53lGmbUAAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2024/02/22/change_healthcare_outage/
[11] https://www.theregister.com/2024/03/08/change_healthcare_restores_first_system/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjFp@BNmhsjJFw53lGmbUAAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/
[14] https://www.theregister.com/2024/04/23/unitedhealth_admits_breach_substantial/
[15] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[16] https://twitter.com/amvinfe/status/1783074702111424760
[17] https://www.suspectfile.com/united-healthcare-optum-and-change-healthcare-involved-in-northeast-ohio-neighborhood-health-data-breach/
[18] https://www.theregister.com/2024/04/23/unitedhealth_admits_breach_substantial/
[19] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/
[20] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[21] https://www.theregister.com/2024/03/14/change_healthcare_ransomware_investigation/
[22] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/
[23] https://whitepapers.theregister.com/
And off to jail you go
Willfully paying organised criminals? Isn't that already an offence?
If it can be argued that the ransomware crooks are Terrorists, then paying them is already an offence, even in the US.
Attacking critical health infrastructure certainly sounds like it could fit the definition of terrorism ...
Re: And off to jail you go
You can argue it all you want, but it still won't be true. It's perfectly legal to pay them unless the particular group you're paying happens to be on a sanctions list.
It *should* be a criminal offense. Not because guys like that should go to jail, but because they shouldn't have to make the decision... and the decision not to pay only really works if there's nearly universal solidarity behind it anyway. By outlawing paying, you can really affect the attacker's calculations ahead of time.
Too pissed to read much...
...but:
UnitedHealth CEO: 'Decision to pay ransom was mine'
Fuck you too, Charlie! I hope you wind up living in a card board box giving blow jobs for hot dog money!
Odd
It's a weird Americanism that CEO's of corporations get called up to explain themselves in front of Senate committees like they're naughty schoolboys and nobody else seems to think it's odd.
I wonder what would happen if this CEO tells the Headmaster that how he runs the business is none of theirs?
Re: Odd
Contempt of Congress can be punished with imprisonment. They have the power to summon *anyone* and force them to answer *any* question, under oath. In public, if they want to. It's a constitutional power, too, not something that an easily be changed.
I suspect it's not a uniquely American thing, either. I think the *UK's* particular style would be more to make you explain yourself to the Minister of This or That in private, but even there I suspect that refusing to talk to the Minister would be a bad move. Other countries do various other things.
Oh, and on edit: In this particular case, I doubt he was very reluctant to begin with. Lets him get his story out there.
Citrix multifactor authentication already hacked
“A vulnerability that allows attackers to bypass [1]multifactor authentication and access enterprise networks using hardware sold by Citrix is under mass exploitation by ransomware hackers despite a patch being available for three weeks.”
Appariently Citrix multifactor authentication runs on an APP on your phone or a SMS msg. As such it's as vulnerable to bugs as any other software. A better solution would be a hardware dongle that issues a challenge-response request on login.
[1] https://arstechnica.com/security/2023/10/critical-citrix-bleed-vulnerability-allowing-mfa-bypass-comes-under-mass-exploitation/
The stupid
It literally burns.