Desk live·
ForensicPost
Ransomware/Identity/File 24-0212

Change Healthcare Intruders Used a Citrix Portal With No Second Factor

Intruders entered Change Healthcare with a working username and password on a Citrix remote-access portal that had no second factor. Company policy required one on every external system.

Constructed geometry · not a chart of case data
JurisdictionUSANashville, Tennesseethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetChange Healthcare
ActorALPHV
D. Kennedy13 min readConfidence: high4 sources reviewed

On 12 February 2024 somebody logged in to a Citrix remote-access portal belonging to Change Healthcare using credentials that worked. There was no second factor on that portal to stop them, and the company’s own policy said there should have been one on every externally facing system.

This is not a reconstruction. It is what the chief executive of the parent company told a congressional committee under oath, which makes it among the best-established initial-access accounts in this database.

The Gap Between The Policy And The Estate

A written requirement that multi-factor authentication be enabled everywhere is not a control. It is a statement of intent that somebody then has to enforce against an estate nobody has completely inventoried.

Testimony indicated the security function was aware the portal lacked the factor. That detail is what separates this from an oversight: the exposure was known and had not been closed.

Where The Credential Came From Is A Separate Question

The account has consistently been described as compromised rather than guessed or brute-forced, and this desk has not seen an established account of how it was obtained. That is recorded as not established rather than filled in.

It matters because the two possibilities imply different failures. A credential harvested from an employee’s personal machine months earlier is a supply problem; a credential phished the previous week is a training problem; neither is fixed by the same work.

The Corpus Keeps Finding This Shape

A valid credential against a remote-access surface, with the second factor absent rather than defeated. It generates almost no forensic noise, because from the system’s side nothing unusual happened at all.

It also generates almost no documentation. A named vulnerability produces an advisory, a patch and a CVE; a working password produces a login record indistinguishable from every other login record, which is one reason this database over-covers exploitation.

How we reported this

Compiled from contemporaneous reporting of congressional testimony by UnitedHealth Group’s chief executive and from published summaries, listed below. This desk has not reviewed the transcript directly. Graded high: the account of the initial access originates with the company under oath rather than with a researcher or an attacker. How the credential was obtained is not established and is not guessed at here. Corrections: corrections@forensicpost.com.

Sources
  1. Change Healthcare responding to cyberattackHIPAA Journal
  2. UnitedHealth CEO on the Change Healthcare ransomThe Register
  3. The Change Healthcare cyberattackCongressional Research Service
  4. Lessons from the Change Healthcare breachCensinet
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary