Desk live·
ForensicPost
Ransomware/Extortion/File 24-0405

They Paid the Operator, and the Affiliate Still Had the Data

ALPHV took the twenty-two million, did not pass the affiliate its share, and shut down. The affiliate kept its copy and extorted the same victim again under a different brand.

Constructed geometry · not a chart of case data
JurisdictionUSANashville, Tennesseethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetChange Healthcare
ActorRansomHub
S. Rosler14 min readConfidence: medium3 sources reviewed

The payment described at 24-0301 went to the operator of the ALPHV franchise. Reporting since holds that the operator kept it, did not pay the affiliate who had actually carried out the intrusion, and closed the operation — an exit scam against its own contractor.

The affiliate still had the four terabytes. In April 2024 the same data was used to extort Change Healthcare a second time, under the RansomHub name.

This Is The Clearest Case In The Corpus Of What A Ransom Does Not Buy

The desk has written repeatedly that an undertaking not to publish has no enforcement mechanism. That is usually an argument from structure: there is no contract, no jurisdiction and no recourse.

Here it is not an argument. The undertaking was given by a party that did not hold the data, to a victim that had no way to know, and it failed within weeks in the most direct way available.

The Franchise Structure Is The Reason

A ransomware-as-a-service operation splits the work: the operator supplies the encryptor, the leak site and the brand, the affiliate supplies the intrusion, and the two split the proceeds. The corpus set that out at 25-0525 from a leaked affiliate panel.

A victim negotiating with the brand is negotiating with the party that holds the least. The stolen files sit with the affiliate, on the affiliate’s infrastructure, and nothing about paying the operator changes that.

What A Defender Can Take From It

Not that paying is wrong — the corpus does not make that argument, and the decision at 24-0301 was made under conditions almost no reader will face. What follows is narrower and harder to dispute: a suppression payment should be modelled as buying nothing, because in the one fully documented case it bought nothing.

Restoration is different. A decryptor either works or it does not, and that can be tested on the day.

Graded medium. That the second extortion happened is well established; the account of the operator withholding the affiliate’s share comes from criminal-forum activity and researcher reporting, and no party to it has confirmed anything.

How we reported this

Compiled from contemporaneous reporting, listed below. The second extortion attempt is established by the leak-site posting and subsequent coverage. The exit-scam account — that the operator retained the affiliate’s share and closed the operation — rests on criminal-forum posts read by researchers, is not confirmed by any party, and is recorded here as a reported account rather than a fact. Graded medium for that reason. Corrections: corrections@forensicpost.com.

Sources
  1. Change Healthcare data breach: what happened and what to doSecurity.org
  2. Change Healthcare responding to cyberattackHIPAA Journal
  3. The Change Healthcare ransomware attack: a landmark breachBlackFog
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary