October 9, 2026

How One Stolen Login Exposed Data on 192.7 Million People at Change Healthcare

One stolen support-desk login, a portal with no MFA, and nine days before anyone noticed led to about $3 billion in costs. ORION Labs maps each path the data takes and where it could be stopped.

Oreen Livni SheinSecurity Engineer and Researcher

Key Takeaways:

  • Put MFA on every remote-access portal, not just admin logins. Change Healthcare's Citrix portal let in a basic customer-support account with nothing but a password, as UnitedHealth’s CEO told the Senate.
  • Treat low-level accounts as a way in. Nebraska alleges that a support login with no admin rights led to the server running Change’s medication-management app, and from there to new administrator accounts.
  • See how data moves, not only what’s in it. In ORION’s Data Loss Threat Model, changes in identity, lineage, and destination could have exposed the attack while the data was still moving.
  • Watch the days before ransomware, not just the encryption. Change says the data was taken Feb. 17–20, 2024, and Nebraska alleges no one noticed until the attacker began encrypting systems over a week after getting in.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Introduction

Somewhere in your company right now there may be a support-desk account no one gives a second thought about, but has just enough access to create major havoc if it fell in the hands of a hacker. 

Change Healthcare had one of those, and around Feb. 11, 2024, according to a State of Nebraska lawsuit, the account's username and password turned up in a Telegram instant messaging group chat that advertised the sale of stolen credentials. 

The next day, somebody used the credentials to access Change's Citrix portal. Over the next nine days, according to Nebraska, the attacker used that single account to walk through a company whose platforms touch an estimated one in three U.S. patient records, broke into a medication-management server, made itself an administrator, and carried the data out. According to Nebraska, nobody noticed until the ransomware hit. 

What Was Taken in the Change Healthcare Breach

The federal breach register lists 192.7 million people affected, the largest entry the Department of Health and Human Services has ever published.

Patients don’t typically deal with Change directly because it’s part of the plumbing, processing roughly 15 billion transactions a year. When a pharmacist checks whether your insurance covers a prescription, or a hospital sends a claim to an insurer, the transaction may have passed through the Change clearinghouse on the way. To process them, Change handles a steady flow of sensitive data.

When Change went dark on Feb. 21, 2024, nine days after infiltration, pharmacies couldn't process prescription claims and payments to hospitals stalled. Change's notice of data breach says the data, which varied by person, may have included:

  • Names, addresses, dates of birth, and contact details
  • Health insurance and member ID information
  • Medical record numbers, providers, diagnoses, medicines, test results, and details of care and treatment
  • Billing and claims data
  • Social Security numbers for some people (Change says most were not affected), and driver's license or other ID numbers in rare instances

Now consider what a victim can actually do about each item. Unlike a credit card, which an issuer can cancel and replace, a Social Security number is rarely changed: SSA says an identity-theft victim may qualify only after trying to fix the problems and still being affected by the misuse. A diagnosis can’t be “replaced” at all—once it’s been read by another party, your private information has been disclosed. That’s why this breach has no natural end date.

How the Data Breach Started

The best public account of the entry comes from a lawsuit. In December 2024, the State of Nebraska sued Change, UnitedHealth, and Optum. The case is pending; in November 2025, a judge denied the defendants' motion to dismiss, and the allegations remain unproven.

According to the State, on or about Feb. 11,  2024, the username and password for "a low-level, customer support employee's access to Change's Citrix portal" were posted in a "Telegram group chat that advertises the sale of stolen credentials." This particular account was "a basic, user-level account," with a handful of applications and no administrator rights.

Andrew Witty, UnitedHealth's chief executive, told the Senate something similar. "On February 12, criminals used compromised credentials to remotely access a Change Healthcare Citrix portal," his written testimony said. Witty added,  "The portal did not have multi-factor authentication."

The CISA's advisory on the group that claimed the attack describes affiliates who phone employees, pretend to be the help desk, and ask for their password. 

From a Support Desk to the Medication Server

A support agent's account typically may access a ticketing tool, customer lookup, or a shared drive or two. Nebraska alleges that from the accessed account, the attacker "was able to break into the server that hosted Change's medication management application, SelectRX." 

That’s a big jump from a help desk screen to a production system running Change's medication-management application. Change's network, the state said, lacked segmentation "both horizontally and vertically," which, the State alleges, let the attacker "move easily across Change systems".

"From there," the State alleged, "the hacker created privileged accounts with administrator capabilities." Nebraska alleges these accounts could access and delete "any and all files" and change "system configurations. According to the State, it simply created new ones and, the State alleges, those actions "still went undetected." Witty put it more carefully, telling the Senate the actor "moved laterally within the systems in more sophisticated ways and exfiltrated data." 

Nebraska's central allegation is that the breach "went undetected by Defendants until the hacker revealed itself when it began to encrypt Change's systems over a week later." Change says the data was taken between Feb 17 and Feb 20, 2024, but how it left, and where it went, has never been disclosed. 

The ORION Data Loss Threat Model maps 14 ways data leaves an organization, and the route used here is undisclosed. In other incidents, CISA reports that ALPHV affiliates have used "Mega.nz or Dropbox" to move victim data, which on the ORION Threat Model is path T3, an upload to an untrusted application such as personal file storage.

Two Extortions and a Rebuilt IT Infrastructure

Nebraska records a ransom payment "of approximately $22 million" on or about March 3, and then, in April, "another group began leaking files of stolen Change data after an affiliate of BlackCat alleged it never received their cut." After the company paid, the second group claimed it held the same stolen data.

Meanwhile, Witty told the Senate the team "replaced thousands of laptops, rotated credentials, rebuilt Change Healthcare's data center network and core services." Nebraska alleges Change chose to rebuild because it "was unable to check every system and interface for backdoors" and its backups had also been compromised.

Why the Breach Cost More than the Headline Number

Headlines on the data breach often carried the figure of $872 million. That’s because UnitedHealth's first-quarter earnings release, filed in April 2024 while the systems were still coming back, reports "$872 million in unfavorable cyberattack effects." But that’s not where it ended.

In its  10-K for 2024 filed in early 2025, UnitedHealth says it "incurred $2.2 billion of direct response costs." Beside that sits "estimated business disruption impacts of $867 million" at Optum Insight, lost revenue while it maintained full readiness of the affected Change Healthcare services.

Direct response costs include the interest-free loan program, extra medical costs while some care management was paused, network restoration, and notifying affected people. 

Business disruption is the cost of a claims clearinghouse that couldn't clear claims, which left providers unable to bill or get paid. Then there is the ransom, about a hundredth of the direct response costs, which Witty called "one of the hardest decisions I've ever had to make" and which he confirmed to senators was $22 million. 

Together, that is about $3 billion for 2024, plus a $799 million reserve in late 2025 for provider loans and other balances it may not collect, before the litigation and whatever regulators eventually decide.

What the State Says Was Missing for Protection

Nebraska's original complaint is specific about what it says Change Healthcare lacked:

  • MFA. The targeted portal did not have it, "in violation of UHG's own stated policies."
  • Detection. A failure "to use sufficient endpoint detection and response (EDR) or user behavioral analysis (UBA) tools, allowing the threat actor to go undetected for 9 days."
  • Segmentation. A failure "to properly segment Change systems, both horizontally and vertically, allowing the threat actor to move easily across Change systems."
  • Isolated backups. They "were not isolated from the primary," so the attacker took out both.

Only the MFA would have stopped the login. The other failures help explain how one compromised credential turned into a massive breach.

Viewed through the ORION Data Loss Threat Model, this breach started with a security gap: a remote access portal was left without MFA. A malicious actor exploited that gap, entered with stolen credentials, moved through the environment, and exfiltrated data. 

Traditional, policy-based DLP likely would not have caught this. Every file that left Change Healthcare was the kind of data those types of systems handle every day, and it was accessed by an account with permission to reach it. A policy engine sees ordinary work, right up until the ransomware hits.

How the ORION Platform Would Have Seen It

The approach to data loss prevention decides everything. ORION runs as an endpoint sensor, a browser extension, and API connectors into SaaS and email. The surface that mattered at Change Healthcare was the endpoint.

The attacker first entered through a Citrix virtual desktop and, Nebraska alleges, spent nine days moving through Change's systems, and a virtual desktop is a full desktop session—an endpoint in every sense. With ORION's endpoint sensor on a VDI session, every file action inside the session is recorded as a movement, which six agents read as it happens.

  • Classification reads the content itself and tags it, HIPAA, PII, PCI, without a scan having run first.
  • Lineage is the movement record: where a file came from, what was done to it (download, copy, zip, encrypt, rename), and where it went.
  • Identity knows who is moving it, from the IdP and HR: title, department, employment start date.
  • Environment adds the where and when. Network zone, geography, time of day.
  • External relations asks whether the destination is a real counterparty, checking the CRM for a contract or a BAA.
  • Analysis takes all of it and returns a verdict: allow, warn (asking the user to justify the action), or deny, then enforces it inline.

Run the nine days, as Nebraska describes them, through those agents with the sensor on the desktops the attacker worked from, and the picture is not subtle.

This is the kind of sequence ORION is built to detect: a support account suddenly accessing sensitive data it has never touched before, newly created administrator accounts gathering records, and those records moving to an untrusted destination. Each step adds context that the activity isn’t normal, creating opportunities to intervene before the data leaves the environment.

What Happens After the Block

Blocking the data from leaving is only the first step. Security teams also need to contain the incident and determine exactly what the attacker accessed and moved. 

  • Response. The alert lands in a SOAR like Torq with the source, the trigger reason, and the full lineage attached, so a playbook can, for example, end the session, isolate the host, and open the ticket without an analyst first assembling context.
  • Evidence. Nebraska's Attorney General notes that residents began receiving notices "nearly five months after the breach was discovered," per its announcement. A lineage record that already lists every file that moved, from where and by which account, turns that reconstruction into a query.
  • Where ORION fits. ORION works alongside MFA, segmentation and EDR rather than replacing them. Across endpoints, browsers, SaaS integrations, and email, it answers the question those controls don't ask at the moment the data moves: should this be happening, given who is moving it, what it is, and where it is going?

Conclusion

Change Healthcare is the clearest case in years of an ordinary intrusion producing a historic outcome, and the whole distance between those two facts is that over the course of nine days, nothing caught it. 

A support-desk password Nebraska says was posted on Telegram allegedly accessed a medication-management server, became administrator accounts, and resulted in the largest entry on the federal breach register, and Nebraska alleges the attack went undetected until the ransomware hit.

So look at your own organization and ask the second question. How long could a stolen login move around in there before anything or anyone noticed? Book a demo, and we will walk your data movement paths against the 14 in the threat model.

FAQs

How did the attackers get into Change Healthcare?

With a stolen username and password on a Citrix remote-access portal that had no multi-factor authentication. Nebraska's lawsuit alleges the credentials belonged to a customer-support employee and had been posted in a Telegram group chat around the day before.

How many people were affected?

192.7 million, the largest breach on the HHS register.

What did the Change Healthcare breach cost?

UnitedHealth's annual report records $2.2 billion in direct response costs for 2024, plus $867 million in business disruption at Optum Insight.

Why did it take nine days to detect?

The intrusion began with a valid login, so nothing at the perimeter was violated, and Nebraska alleges Change lacked sufficient endpoint detection and behavior analysis and had not properly segmented its systems.

Would DLP have prevented this breach?

Not policy-based DLP on its own, because every file moved was legitimately sensitive and moved by an intruder who entered with a stolen login, so a rule-matching engine sees expected behavior. Catching it inside the nine days means watching how data moves rather than what it contains.

Sources

‍

The DLP renaissance, as it unfolds

ORION Labs Case Files

How One Stolen Login Exposed Data on 192.7 Million People at Change Healthcare

One stolen support-desk login, a portal with no MFA, and nine days before anyone noticed led to about $3 billion in costs. ORION Labs maps each path the data takes and where it could be stopped.

October 9, 2026
ORION Labs Case Files

How 12,000 Files Left Pfizer Through a Personal Google Drive

A departing employee's USB drive was blocked, but logs of the employee's uploads to a personal Google Drive went unread for six days. ORION Labs maps each path the data takes and where it could be stopped.

October 8, 2026
Guides & Explainers

How Much Does Enterprise DLP Cost?

Published DLP list prices run about $50 to $144 per user a year. See how vendors price it, what drives cost up, and the people cost most budgets miss.

October 6, 2026