Ransomware group Blackcat is behind cyberattack on UnitedHealth division, company says
Summary
Changes parent company UnitedHealth Group said it discovered that a cyber threat actor breached part of the units information technology network on Feb. 21, according to a filing with the SEC. UnitedHealth isolated and disconnected the impacted systems "immediately upon detection" of the threat, the filing said, but it didnt disclose the nature of the attack or exactly when it took place. Blackcat, also called Noberus and ALPHV, steals sensitive data from institutions and threatens to publish it unless a ransom is paid, according to a December release from the U.S. Department of Justice. Brett Callow, a threat analyst at the cybersecurity company Emsisoft, said ransomware groups will often make posts like these in an effort to bring victims to the negotiating table. Ransomware attacks can be particularly dangerous within the health-care sector, as they can cause immediate harm to patients physical safety, said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association.