Between the login on 12 February and the encryption on 21 February, intruders moved through Change Healthcare’s network and removed a reported four terabytes of data. Nine days.
The Encryption Is The Announcement, Not The Attack
By the time anything was visible, the part that produced 192.7 million notifications was already complete. Encryption is the moment the attacker chooses to be seen, and it happens after the theft because the theft is the leverage.
An organisation that recovered perfectly from backups on 22 February would still have faced everything that followed. This corpus files that under double extortion; here it is the whole story.
Nine Days Is Not Unusually Long
It is close to the median in vendor incident-response caseloads and shorter than many cases in this database. The scale of the outcome came from where the intruders were, not from how long they had.
Change Healthcare processes claims and payments between providers and insurers. A processor sits where the records of many organisations converge, which is why nine days there produced more exposure than months elsewhere.
What The Outage Did
Taking the systems down severed claims and payment routing across a large part of the United States health system. Providers went unpaid, pharmacies could not verify coverage, and some practices took emergency loans.
That harm is availability, not confidentiality, and it generated no notification of its own. The corpus records at 25-0708 that availability harm is measured mainly by insurers; this is the case where it was measured by everybody.
Compiled from contemporaneous reporting and company statements, listed below. The nine-day interval and the four-terabyte volume are as reported; this desk has not seen a company figure for the volume and treats it as an estimate rather than an established total. The operational consequences described are widely reported but are not quantified here. Corrections: corrections@forensicpost.com.
- The Change Healthcare ransomware attack: a landmark breachBlackFog
- Change Healthcare’s ransomware attackThe Register
- The Change Healthcare cyberattackCongressional Research Service