Hacker News new | past | comments | ask | show | jobs | submit login
Change Healthcare hackers used stolen credentials and no MFA, says UHG CEO (techcrunch.com)
15 points by skilled 20 days ago | hide | past | favorite | 10 comments



Related,

Hackers Broke into Change Healthcare's Systems 9 Days Before Cyberattack (https://news.ycombinator.com/item?id=40127483) - Apr 2024 (27 comments)

BlackCat ransomware group implodes after apparent payment by Change Healthcare (https://news.ycombinator.com/item?id=39610846) - Mar 2024 (162 comments)

UnitedHealth says Change hackers stole health data on ‘substantial proportion of people in America’ (https://techcrunch.com/2024/04/22/unitedhealth-change-health...)


The title is not correct. They used credentials to get access to the vpn. How they moved laterally is obviously the interesting part anyway. Change the title, it gives cover to the lumbering behemoth that fault might lie anywhere besides UnitedHealths corrupt IT.


You are correct. I made a mistake with the title, it should say that access was acquired through a Citrix account without MFA as opposed to a direct Citrix bug. My bad. I will email mods to change it.

This Reuters[0] article is much more specific about saying it was a Citrix vulnerability, but since Citrix has not issued an official statement, it's better to have it changed to the default title.

[0]: https://www.reuters.com/technology/cybersecurity/unitedhealt...


Fixed now. Thanks!

(Submitted title was "UnitedHealth hackers exploited Citrix bug, CEO says")


How they moved laterally was likely trivial. Every place that I seen with a VPN tends to trust everything within the VPN.


Check the network share for a folder called "Passwords"


Mandate MFA/passkeys/crypto primitives using regulatory mechanisms.


* And no lame half-measures involving code-by-SMS or code-by-email.


I have relatives with a small business whose Verizon phones were allegedly taken over and then used code by SMS to get into a bunch of other things.

And then Verizon allegedly allowed it to happen again a few days later after they had thought the original phones/sims shut down


Screw Change Healthcare. I had the misfortune of dealing with them once as a vendor years ago. Horrible DevSecOps culture due to penny pinching.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: