On 12 February 2024 somebody logged in to a Citrix remote-access portal belonging to Change Healthcare using credentials that worked. There was no second factor on that portal to stop them, and the company’s own policy said there should have been one on every externally facing system.
This is not a reconstruction. It is what the chief executive of the parent company told a congressional committee under oath, which makes it among the best-established initial-access accounts in this database.
The Gap Between The Policy And The Estate
A written requirement that multi-factor authentication be enabled everywhere is not a control. It is a statement of intent that somebody then has to enforce against an estate nobody has completely inventoried.
Testimony indicated the security function was aware the portal lacked the factor. That detail is what separates this from an oversight: the exposure was known and had not been closed.
Where The Credential Came From Is A Separate Question
The account has consistently been described as compromised rather than guessed or brute-forced, and this desk has not seen an established account of how it was obtained. That is recorded as not established rather than filled in.
It matters because the two possibilities imply different failures. A credential harvested from an employee’s personal machine months earlier is a supply problem; a credential phished the previous week is a training problem; neither is fixed by the same work.
The Corpus Keeps Finding This Shape
A valid credential against a remote-access surface, with the second factor absent rather than defeated. It generates almost no forensic noise, because from the system’s side nothing unusual happened at all.
It also generates almost no documentation. A named vulnerability produces an advisory, a patch and a CVE; a working password produces a login record indistinguishable from every other login record, which is one reason this database over-covers exploitation.
Compiled from contemporaneous reporting of congressional testimony by UnitedHealth Group’s chief executive and from published summaries, listed below. This desk has not reviewed the transcript directly. Graded high: the account of the initial access originates with the company under oath rather than with a researcher or an attacker. How the credential was obtained is not established and is not guessed at here. Corrections: corrections@forensicpost.com.
- Change Healthcare responding to cyberattackHIPAA Journal
- UnitedHealth CEO on the Change Healthcare ransomThe Register
- The Change Healthcare cyberattackCongressional Research Service
- Lessons from the Change Healthcare breachCensinet