Security News > 2024 > April > UnitedHealth confirms it paid ransomware gang to stop data leak

The UnitedHealth Group has confirmed that it paid a ransom to cybercriminals to protect sensitive data stolen during the Optum ransomware attack in late February.
The BlackCat/ALPHV ransomware gang claimed the attack, alleging to have stolen 6TB of sensitive patient data.
BleepingComputer checked RansomHub's data leak website and can confirm that the threat actor has removed UnitedHealth from its list of victims.
Yesterday, UnitedHealth posted an update on its website announcing support for people whose data had been exposed by the February ransomware attack, officially confirming the data breach incident.
Ransomware gang starts leaking alleged stolen Change Healthcare data.
US govt probes if ransomware gang stole Change Healthcare data.
News URL
Related news
- Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures (source)
- Cardiff's children's chief confirms data leak 2 months after cyber risk was 'escalated' (source)
- BlackLock Ransomware Exposed After Researchers Exploit Leak Site Vulnerability (source)
- Royal Mail investigates data leak claims, no impact on operations (source)
- Everest ransomware's dark web leak site defaced, now offline (source)
- Western Sydney University discloses security breaches, data leak (source)
- Interlock ransomware claims DaVita attack, leaks stolen data (source)
- Microsoft Warns Default Helm Charts Could Leave Kubernetes Apps Exposed to Data Leaks (source)
- New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy (source)