According to UnitedHealth CEO Andrew Witty’s congressional testimony, reported by BleepingComputer, criminals used compromised employee credentials on 12 February 2024 to sign into a Change Healthcare Citrix portal used for remote desktop access. The portal did not have multi-factor authentication. Once inside, the actors moved laterally, exfiltrated data over roughly nine to ten days, and deployed ransomware around 21 February 2024. Public reporting does not establish whether the password was stolen by phishing or by information-stealing malware, and it does not prove that any single publicly reported credential dump was the login used that day.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did the attackers get into Change Healthcare?

The attackers got into Change Healthcare by signing into a workforce Citrix remote-access portal with compromised employee credentials on 12 February 2024. According to UnitedHealth CEO Andrew Witty’s written congressional testimony, via BleepingComputer, that portal did not require multi-factor authentication, so the password alone was enough for remote desktop access. From that foothold the threat actor moved laterally inside Change Healthcare systems and later deployed ransomware.

Was MFA bypassed, or was it simply missing?

MFA was missing on the Change Healthcare Citrix portal that was used for initial access. Witty’s testimony states the portal did not have multi-factor authentication, not that a second factor was defeated in real time. A password-only remote-access login is a single-factor door. Public reporting does not describe push fatigue, AiTM relay, device-code abuse, or a helpdesk TAP handoff on that first Citrix sign-in.

Do we know how the employee password was stolen?

Public reporting does not establish how the Change Healthcare employee credentials were stolen. UnitedHealth did not confirm phishing versus information-stealing malware as the theft method. Hudson Rock separately reported Citrix-related credentials tied to a Change Healthcare employee around 8 February 2024, but public reporting does not establish that those credentials were the ones used on 12 February. Treat the theft method as unconfirmed and focus on the documented fact: a password worked alone on the portal.

Why did ransomware still land after the Citrix login?

Ransomware still landed because initial access was only the first phase of the Change Healthcare incident. After the password-only Citrix session existed, the actors spent roughly nine to ten days moving laterally and exfiltrating data before encryption around 21 February 2024. Login MFA on the original portal would have been relevant at the door. It does not undo a live internal session, stop bulk theft once the attacker is inside, or prevent ransomware deployed days later. ALPHV/BlackCat and later RansomHub activity sit in that post-access window.

How bad was the operational and financial hit?

The Change Healthcare ransomware disruption hit nationwide claims, prescription, and payment processing, with estimated financial damages around $872 million according to BleepingComputer reporting on the incident. BlackCat claimed a $22 million ransom receipt; UnitedHealth confirmed it paid a ransom, though public reporting does not establish the exact amount paid. Payment processing later recovered to about 86% of pre-incident levels in testimony coverage. Leaked samples contained PHI and PII; the company reported no evidence that full doctors’ charts or complete medical histories were taken. Public reporting does not establish an exact count of individuals or records affected.