On the first of March, 2024, a transfer of roughly 350 bitcoin, worth about $22 million that morning, landed in a cryptocurrency wallet that blockchain analysts had been watching for weeks. The wallet belonged to a criminal enterprise called ALPHV. The money came, by every available indication, from UnitedHealth Group, the largest health insurer in the United States, and it was meant to buy back the medical records of most of the country.
Within days the sellers had stolen the payment from their own contractor, faked their own arrest, and disappeared. The contractor, cheated of a fee somewhere north of $17 million, went public with a grievance and a reminder: they still had the files. Six weeks after that, a different gang put the same stolen data up for sale and demanded that UnitedHealth pay again.
Nobody has been arrested. The final count of people whose records were taken stands at 192.7 million, about 57 percent of the U.S. population. And in the entire chain of transactions, the only party that did what it said it would do was the victim.
The operators
ALPHV, also known as BlackCat, was not a gang in the old sense. It was a platform. Its operators wrote the encryption malware, ran the darknet site where victims' names and stolen files were posted, and maintained the negotiation portal through which ransoms were haggled. The break-ins themselves were done by independent contractors the trade calls affiliates, who rented the tooling and kept most of each ransom, typically 80 to 90 percent, with the operators skimming the remainder from a wallet they controlled.
The crew behind ALPHV was on its third name. As DarkSide it had shut down the Colonial Pipeline in May 2021 and triggered gasoline shortages along the East Coast, which brought enough heat that the operators rebranded as BlackMatter, and then, in late 2021, as ALPHV. Through 2022 and 2023 it became one of the two or three most prolific ransomware operations in the world.
Ransomware-as-a-service has a structural weakness that everyone in the business understands and nobody can fix: the affiliate and the operator have to trust each other, and neither has any recourse if the other cheats. The victim's payment goes to a wallet the operator controls. The affiliate's share is paid out afterward, on the operator's honor. For years the market's answer to this was reputation. Operators who stiffed their affiliates would find that nobody worked for them. That answer turns out to have a ceiling, and the ceiling is roughly $22 million.
The provocation
On 19 December 2023 the FBI, working with several European police agencies, seized ALPHV's leak site and announced that it had obtained the group's decryption keys, which it offered free to several hundred victims. The site went dark with a law-enforcement banner on it.
It stayed dark for about a day. ALPHV's operators, who evidently still had a copy of the site's cryptographic keys, brought it back online at a new address, posted a message mocking the FBI, and announced a change of policy. Since its founding the group had maintained a rule, common among the larger Russian-speaking ransomware crews, that affiliates were not to attack hospitals or critical infrastructure. Those targets attract too much attention from governments. That rule, the operators said, was now lifted. Affiliates could hit anything except the countries of the former Soviet Union. They were told to go after hospitals in particular.
Two months later, one of them did.
The job
Change Healthcare is a company most Americans had never heard of before February 2024 and most have not heard of since, which is a measure of how thoroughly it was plumbed into the walls. Acquired by UnitedHealth's Optum division in 2022, it operated the clearinghouse through which roughly a third of all U.S. medical claims flowed: pharmacies checking whether a prescription was covered, hospitals submitting bills to insurers, insurers sending payment back. Something on the order of 15 billion transactions a year.
According to the sworn testimony that UnitedHealth's chief executive, Andrew Witty, gave to Congress on 1 May 2024, the intruder entered on 12 February 2024 through a Citrix remote-access portal using a set of stolen employee credentials. The portal was not protected by multi-factor authentication. Witty could not explain why. Change had been acquired sixteen months earlier and the integration of its systems into Optum's security standards was, he said, still under way.
The intruder spent nine days inside. Nine days is a long time in a network; it is enough to map the systems, find the databases, escalate privileges, and move terabytes of data out to servers the attacker controls. By the attacker's own later account, several terabytes were taken. Then, on 21 February, the ransomware was detonated, and Change Healthcare's systems went down.
The effect was immediate and national. Pharmacies could not verify coverage, so patients paid cash or went without. Hospitals and physician practices could not submit claims, so payments stopped. Within weeks the American Hospital Association was reporting that most of its members were losing revenue, and a third of them were losing more than half. UnitedHealth began advancing loans to providers to keep them solvent, an amount that would eventually pass $9 billion.
The payment
Witty told the Senate that the decision to pay was his. "As chief executive officer, the decision to pay a ransom was mine," he said. "This was one of the hardest decisions I've ever had to make." The company has never officially disclosed the amount, but it has never disputed the figure that blockchain analysts and reporters at Wired arrived at from the public ledger: 350 bitcoin, about $22 million, paid on 1 March into a wallet associated with ALPHV.
A ransom payment in this market buys two things, at least in theory. It buys a decryption key, so the victim can unlock its own systems. And it buys a promise that the stolen copy of the data will be deleted rather than published. The first thing is verifiable. The second is not, and never has been.
The double-cross
Within days of the payment, ALPHV's leak site went offline again and came back showing a law-enforcement seizure banner, with the logos of the FBI, the U.K. National Crime Agency, and the other agencies that had participated in December.
Security researchers looked at it for about an hour before concluding it was a fake. It was a copy of the December banner with the wrong details, hosted on ALPHV's own infrastructure, and none of the agencies named on it had any idea what it was. The U.K. agency, asked by reporters, said flatly that it had not conducted any new operation against the group.
What had actually happened became clear on a Russian-language crime forum a day or two later. An affiliate posting under the handle Notchy, who claimed to have carried out the Change Healthcare intrusion, wrote that ALPHV had suspended their account, emptied the wallet, and kept the entire ransom. As proof Notchy posted the wallet address, which matched the one the $22 million had gone into, and which now showed the funds moved out. ALPHV's operators, in a final message, announced that the operation was closing, that the source code for the malware was for sale for $5 million, and that they would not be returning. Then they were gone.
The trade has a name for this, borrowed from cryptocurrency fraud: an exit scam. ALPHV had been operating for over two years and had collected, by the FBI's estimate, hundreds of millions of dollars. Its reputation with affiliates was its principal asset. A $22 million single payment, the largest in the group's history, turned out to be worth more than the reputation.
Notchy's forum post ended with the sentence that made the story a story rather than a footnote. The affiliate noted, for whatever audience such a note has, that the data had never been on ALPHV's servers. It was still in Notchy's possession. The deletion that UnitedHealth had paid for could not have been performed by the party it paid, because that party had never had the goods.
The second act
In early April 2024 a new operation calling itself RansomHub, which had been recruiting displaced ALPHV affiliates, posted a listing for Change Healthcare on its own leak site. The listing claimed possession of four terabytes of data, including patient records, insurance details, contracts, and the personal information of active military personnel, and it gave UnitedHealth twelve days to pay before the files would be sold to the highest bidder. To prove the claim, RansomHub published a set of screenshots: contracts between Change and its clients, a claims record, a billing file.
RansomHub's message named the ALPHV theft directly. The gang said it had been approached by the affiliate who was owed the money and was, in effect, collecting on the debt. UnitedHealth had paid ALPHV; it had not paid the person who actually held the data; and so the data was for sale.
Roughly a week after the deadline the listing disappeared. UnitedHealth has never said whether it paid a second time, and no second payment has been traced on the blockchain with the confidence of the first. A listing that vanishes without a leak is, in this market, usually read one way. It is also sometimes read the other way, as a gang that never had the full archive quietly dropping a bluff. Nobody outside the two parties knows.
RansomHub itself went dark in April 2025, its infrastructure offline and its affiliates scattering to other groups, in a pattern that by then looked less like a disruption than like the ordinary life cycle of the business.
The bill
UnitedHealth put the cost of the episode to itself at about $3 billion for 2024, roughly a third of it in direct response costs and the rest in lost business while Change was rebuilt. The provider loans exceeded $9 billion. The count of affected individuals was revised upward for eighteen months, from "500 or more" in the initial breach notice to 100 million in October 2024, to 190 million in January 2025, to 192.7 million in July 2025. The company has said it expects no further revisions.
Congress held hearings. The Department of Health and Human Services opened an investigation under the health privacy statute. Class actions were consolidated in federal court in Minnesota. The multi-factor authentication gap became the standard example in every subsequent discussion of healthcare cybersecurity. None of this touched the people who took the data, who are believed to be in Russia, and who are not coming to Minnesota.
The counterparty problem
Set the human damage aside for a moment, because the story has a structural point that survives without it.
A ransom payment is a contract with a counterparty who has already demonstrated a willingness to commit crimes. The payer's only protection is the counterparty's interest in being paid again by the next victim. That interest is real, and it is the reason the market functions at all. But it is a market-level interest, held by the brand, and the brand can be abandoned. The moment a single payment exceeds the present value of the brand, the rational move for the operator is to take it and start over under a new name. ALPHV had already done this twice. The affiliates, whose entire livelihood depends on the operators' honesty, have no more protection than the victims.
So UnitedHealth paid $22 million for a deletion that the recipient could not perform, to a counterparty that immediately defrauded its own partner, and then faced a second demand from a third party who had inherited the grievance along with the files. Every actor in the chain behaved exactly as its incentives dictated. The affiliate did the work and expected to be paid. The operators saw a number large enough to retire on and retired. The second gang saw an unpaid debt and a motivated seller. And the victim, which had been told that paying would make the problem go away, discovered that it had bought nothing but a decryption key and a place in a longer story.
Compiled from public reporting by Wired, Krebs on Security, Reuters, and BleepingComputer, and from UnitedHealth Group's testimony to the Senate Finance Committee and the House Energy and Commerce Committee on 1 May 2024. Figures for the ransom amount and the wallet are from public blockchain analysis and have not been confirmed by UnitedHealth. Whether a second payment was made to RansomHub is unknown.