Desk live·
ForensicPost
Ransomware/Dwell/File 24-0221

The Change Healthcare Theft and the Ransomware Were a Week Apart

The theft and the ransomware were separate events more than a week apart. Only the second one was visible, and by then the first was finished.

Constructed geometry · not a chart of case data
JurisdictionUSANashville, Tennesseethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetChange Healthcare
ActorALPHV
S. Rosler12 min readConfidence: high3 sources reviewed

Between the login on 12 February and the encryption on 21 February, intruders moved through Change Healthcare’s network and removed a reported four terabytes of data. Nine days.

The intrusionContemporaneous reporting and company testimony
TimeEventEvidence
12 February 2024Access via Citrix portal using valid credentialsCompany testimony
12–20 FebruaryLateral movement; approximately 4TB removedReported
21 February 2024Ransomware deployed; systems taken offlineCompany disclosure

The Encryption Is The Announcement, Not The Attack

By the time anything was visible, the part that produced 192.7 million notifications was already complete. Encryption is the moment the attacker chooses to be seen, and it happens after the theft because the theft is the leverage.

An organisation that recovered perfectly from backups on 22 February would still have faced everything that followed. This corpus files that under double extortion; here it is the whole story.

Nine Days Is Not Unusually Long

It is close to the median in vendor incident-response caseloads and shorter than many cases in this database. The scale of the outcome came from where the intruders were, not from how long they had.

Change Healthcare processes claims and payments between providers and insurers. A processor sits where the records of many organisations converge, which is why nine days there produced more exposure than months elsewhere.

What The Outage Did

Taking the systems down severed claims and payment routing across a large part of the United States health system. Providers went unpaid, pharmacies could not verify coverage, and some practices took emergency loans.

That harm is availability, not confidentiality, and it generated no notification of its own. The corpus records at 25-0708 that availability harm is measured mainly by insurers; this is the case where it was measured by everybody.

How we reported this

Compiled from contemporaneous reporting and company statements, listed below. The nine-day interval and the four-terabyte volume are as reported; this desk has not seen a company figure for the volume and treats it as an estimate rather than an established total. The operational consequences described are widely reported but are not quantified here. Corrections: corrections@forensicpost.com.

Sources
  1. The Change Healthcare ransomware attack: a landmark breachBlackFog
  2. Change Healthcare’s ransomware attackThe Register
  3. The Change Healthcare cyberattackCongressional Research Service
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary