Hackers claim to have UnitedHealth's stolen data - is it a bluff?


FILE PHOTO: The corporate logo of the UnitedHealth Group appears on the side of one of their office buildings in Santa Ana, California, U.S., April 13, 2020. REUTERS/Mike Blake/File Photo

WASHINGTON (Reuters) - A freshly formed hacking gang claims to have won access to a massive stash of data stolen from UnitedHealth Group, the largest U.S. health insurer, but with little evidence to go on it is not clear whether they are telling the truth.

Hackers walloped UnitedHealth in February, paralyzing billions of dollars worth of health insurance payments across the country. The ransomware gang "Blackcat" initially said on its website that it had stolen 8 terabytes of sensitive records - including medical insurance and health data - only to swiftly delete the statement without explanation.

The new group, "Ransomhub," told Reuters that a disgruntled affiliate of Blackcat gave the data to them after a botched ransomware payment allowed Blackcat's hackers to vanish with $22 million in bitcoin.

Ransomhub refused to provide any backing for their claim or identify the affiliate.

"We will not disclose any information," the hackers said in a chat.

UnitedHealth said it was aware of the claim and was continuing to work with authorities. The FBI did not immediately return a message.

UnitedHealth has stayed mum on whether it paid the cybercriminals, but a hacker forum posting - backed by forensic blockchain evidence - claimed that Blackcat had cheated an affiliated hacker or hacker group out of a $22 million ransom paid by UnitedHealth to help contain the breach.

Blackcat then pulled a disappearing act, falsely claiming to have been nabbed by law enforcement.

Ransomhub told Reuters the Blackcat affiliate has since handed the data to them for resale. It declined to answer further questions, saying the group was busy.

With so much intrigue already surrounding the hack, experts urged caution about the claim.

Analyst Brett Callow of cybersecurity company Emsisoft said he suspected Ransomhub's claim was true, but he cautioned that he was making "a very low confidence guess" and that the group could be trying out a scam.

Darren Williams, the chief executive of cybersecurity company BlackFog, said he had seen a couple of gangs recently try to boost their credibility by lying about what they had. He said the latest claim was "highly likely" a bluff.

(Reporting by Raphael Satter; Editing by Josie Kao)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

STMicro has shipped 5 billion chips for Starlink in past decade; that could double by 2027
Tech support scammers stole US$85,000 from him. His bank declined to refund him.
Analysis-Old meets new economy: AI boom to supercharge European banks' rally
Humanoid robots take center stage at Silicon Valley summit, but scepticism remains
Asahi CEO mulls new cybersecurity unit as disruption drags on
China's smaller manufacturers look to catch the automation wave
From Zelda to Civ VI: understanding game complexity
From traditional mats to virtual arenas: The rise of VR taekwondo in Malaysia
UK regulation of cryptoassets to start in October 2027, finance ministry says
Windows running slow? Microsoft’s 11 quick fixes to speed up your PC

Others Also Read