The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Yes. UnitedHealth Group CEO Andrew Witty told Congress in May 2024 that attackers used compromised credentials to enter a Change Healthcare Citrix remote-access portal that did not have multifactor authentication (MFA) enabled. The incident was associated in congressional and company records with the ALPHV/BlackCat ransomware operation and affiliates.
That is a more precise explanation than saying “Citrix was hacked.” The public record describes abuse of a valid account: a username and password were accepted by a legacy remote-access system, and the missing second factor allowed the attackers to get inside. From there, they reportedly moved through the environment, reached sensitive systems, stole data and deployed ransomware. MFA was a critical failure, but not the whole root cause.
What happened at Change Healthcare
Change Healthcare’s systems began suffering major disruption on or about February 21, 2024. The company disconnected systems as the attack spread, affecting claims submission and payment, pharmacy transactions, eligibility and authorization workflows, and other healthcare-administration services. The U.S. Department of Health and Human Services (HHS) described the event as a direct threat to patient care and essential healthcare operations (HHS cyberattack letter).
Witty’s congressional testimony says the initial access used compromised credentials against a Citrix portal without MFA (House hearing record). A Senate briefing summary likewise describes the portal as lacking MFA and associates the attack with ALPHV/BlackCat and affiliates (Senate correspondence).
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
A 2025 federal court complaint alleges that credentials for a Change customer-support employee were posted in a Telegram group on February 12, 2024. It describes the account as a basic user account rather than an administrator account. Those details are allegations in litigation, not final judicial findings (complaint PDF).
Timeline of the incident and response
| Date | What the record says |
|---|---|
| February 12, 2024 | A later complaint alleges that the relevant credentials were posted in a Telegram group. |
| February 21, 2024 | Change Healthcare systems began experiencing the attack and widespread operational disruption. |
| March 13, 2024 | HHS’s Office for Civil Rights (OCR) issued a letter addressing the cyberattack and its HIPAA implications (HHS letter). |
| April 30, 2024 | UnitedHealth briefed senators, according to congressional correspondence. |
| May 1, 2024 | CEO Andrew Witty testified before Congress about compromised credentials, the MFA gap and the disruption (hearing record). |
| July 19, 2024 | Change Healthcare reported a breach to HHS. |
| January 24, 2025 | HHS’s later FAQ update said approximately 130 million individual notices had been sent as of this date. |
| March 14, 2025 | The HHS FAQ reported approximately 190 million individuals impacted, using the figures available in that update (HHS FAQ). |
How the reported access path worked
1. A valid account was available to the attackers
The evidence supports compromised-account use, not necessarily exploitation of a newly discovered Citrix software vulnerability. “Stolen Citrix account” means credentials were used to authenticate to a Citrix remote-access service. It does not prove that Citrix software itself was breached.
2. The portal accepted a password without MFA
Because the portal lacked MFA, possession of the username and password was enough for the reported entry. A phishing-resistant factor could have blocked or substantially complicated this particular route, although no authentication control guarantees that every later attack path would fail.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
3. The foothold was followed by broader compromise
Company testimony and litigation records describe an attack that progressed beyond the initial login. The later stages included movement through the environment, access to higher privileges, sensitive-data access, exfiltration and ransomware deployment. The complaint supplies some of the privilege-escalation and account details; those points should remain attributed allegations unless confirmed by a final forensic or legal finding.
Why “no MFA” is not the entire root cause
MFA explains the immediate authentication failure. It does not explain why one user account could lead to a national service outage. That requires examining the rest of the control chain.
- Credential exposure: An attacker first had a usable password. Password hygiene, breach monitoring and phishing resistance therefore mattered before the login prompt.
- Legacy infrastructure: The portal belonged to an older Change environment that had not been brought under the same controls as other UnitedHealth systems, according to congressional discussions.
- Authorization and privilege: Authentication proves who is logging in; authorization determines what that identity can reach. A basic account should not be able to create privileged identities or reach unrelated critical systems.
- Segmentation: Network and application boundaries should limit a remote-access session to the specific resources required for the job.
- Detection and response: Unusual devices, geography, after-hours activity, credential dumping, lateral movement and abnormal file access should generate actionable alerts.
- Resilience: Immutable backups, tested restoration and alternate transaction routes determine whether an intrusion becomes a prolonged national outage.
- Acquisition integration: Connected legacy environments need an inventory, identity review, exception owner and remediation deadline. Ownership by a larger parent does not automatically make controls uniform.
Who was behind the attack?
UnitedHealth, congressional records and related public descriptions associated the incident with ALPHV/BlackCat and affiliates. That attribution should be stated as the characterization in those records. It should not be expanded into a claim that a government carried out the attack unless a government investigation specifically established that conclusion. Criminal groups can also make unreliable or self-serving claims about operations.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What systems and data were affected?
The operational effects reached far beyond Change’s own network. Providers struggled to submit claims and receive reimbursement; pharmacies and patients encountered transaction and prescription-related problems; and eligibility, authorization and payment workflows were interrupted. The Senate Finance Committee’s hearing record documents those operational and policy consequences (hearing).
HHS confirmed that Change reported a breach involving protected health information. Its FAQ says the company initially reported only the statutory minimum of 500 affected individuals while investigating, then reported a much larger impact. The approximately 190 million figure is an HHS update dated March 14, 2025, not a timeless or necessarily final count. “Impacted” also is not identical to “every person whose records were proven stolen.” Distinguish among data potentially accessed, data exfiltrated, people potentially affected and people actually notified.
Why this became a national healthcare crisis
Change Healthcare operated shared transaction infrastructure used by a large portion of the healthcare system. A compromise at that intermediary could interrupt cash flow and administrative work for organizations that were not themselves breached. Healthcare also has unusually low tolerance for downtime: delayed payment can threaten a provider’s ability to operate, while interruptions to pharmacy and authorization workflows can affect access to medication and care.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The Senate Finance Committee and Senator Ron Wyden’s subsequent policy discussion used the incident to question whether major healthcare companies should face mandatory cybersecurity requirements (policy statement). That debate is separate from determining every factual allegation in private lawsuits or congressional criticism.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What UnitedHealth and regulators disclosed
Witty told Congress that attackers used compromised credentials, that the Citrix portal did not have MFA, and that the company was investigating why MFA was absent. He also described widespread operational disruption and an ongoing assessment of data theft and impact (testimony).
HHS OCR opened HIPAA investigations of Change Healthcare and UnitedHealth Group. The agency’s materials address whether protected health information was breached and whether HIPAA requirements, including notification duties, were followed (HHS FAQ). An investigation or agency statement is not automatically a final finding that every allegation in a complaint is true.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Controls healthcare organizations should implement
Identity and MFA
- Require MFA on every externally accessible VPN, Citrix, virtual-desktop, remote-support and vendor connection.
- Use phishing-resistant FIDO2 keys or passkeys for administrators and other high-risk users where feasible.
- Eliminate shared accounts; disable dormant and legacy accounts; monitor breach and criminal-market intelligence for exposed credentials.
- Apply conditional access using device posture, location, risk and session behavior.
- Keep emergency “break-glass” accounts tightly controlled, logged and periodically tested rather than using them as permanent MFA bypasses.
Remote access and segmentation
- Inventory every external access path, including systems inherited through acquisitions.
- Place gateways in hardened segments and limit each session to required applications instead of a broad network.
- Log successful and failed authentication, impossible travel, unfamiliar devices and unusual access times.
Privilege management
- Separate ordinary and administrative accounts and enforce least privilege.
- Use just-in-time elevation and alert on creation of privileged accounts.
- Protect identity providers, domain controllers and backup systems separately.
- Ensure a low-privilege account cannot create or modify privileged identities.
Detection, recovery and continuity
- Monitor credential dumping, remote execution, lateral movement and abnormal file access.
- Maintain immutable or offline backups and test restoration, not just backup completion.
- Maintain secondary claims and payment routes, manual submission procedures and cash-flow contingencies.
- Exercise a scenario in which the primary transaction intermediary is unavailable for weeks.
- Prepare communications for providers, patients, pharmacies, regulators and law enforcement.
M&A governance
- Treat acquired infrastructure as untrusted until assets, identities, privileges, vulnerabilities and logs are reviewed.
- Track every security exception with an accountable executive and a deadline.
- Bring acquired remote-access systems under centralized identity policy as an integration milestone, not an indefinite future project.
Questions security leaders should be able to answer
- Can every external access path enforce MFA, and which exceptions remain?
- Are those exceptions owned, time-limited and monitored?
- Can exposed credentials be detected and disabled quickly?
- Can a low-privilege account reach or create privileged identities?
- Are acquired systems segmented from critical transaction platforms?
- Can claims and payment operations continue without the primary intermediary?
- Have backups, alternate routes and downtime procedures been tested under realistic conditions?
What remains unresolved
- The precise way the initial credentials were obtained.
- The complete dwell time between first access and disruptive activity.
- The full set of systems and records accessed or exfiltrated.
- The final number of affected individuals and how many specific records were confirmed exposed.
- Which security exceptions were documented, approved and assigned during the relevant period.
- The ultimate findings of HHS investigations and civil proceedings.
Frequently Asked Questions
Was this a Citrix software vulnerability?
The public record supports compromised credentials being used against a Citrix remote-access portal without MFA. It does not, by itself, establish that attackers exploited a Citrix software flaw.
Would MFA have prevented the Change Healthcare attack?
MFA could have blocked or complicated the reported password-based entry. It would not by itself solve excessive privileges, weak segmentation, poor monitoring or inadequate downtime preparation.
Is 190 million the final number of people whose data was stolen?
HHS’s March 14, 2025 FAQ said approximately 190 million individuals were impacted. That dated figure should not be treated as a timeless final count or as proof that every person’s records were confirmed stolen.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




