Cyberattacks on health-care organizations continue to be lucrative for bad actors as long as ransoms are paid. For the first time, UnitedHealth admitted to paying the ransom, but data was still stolen and 22 screenshots of compromised files were released on the dark web. (Credit: Song_about_summer/Adobe Stock) Cyberattacks on health-care organizations continue to be lucrative for bad actors as long as ransoms are paid. For the first time, UnitedHealth admitted to paying the ransom, but data was still stolen and 22 screenshots of compromised files were released on the dark web. (Credit: Song_about_summer/Adobe Stock)

Hackers acquired health and personal information about a potentially "substantial proportion" of consumers during the massive Change Healthcare cyberattack, parent company UnitedHealth Group said on Monday.

Hackers usually seek sensitive data such as patient records, medical histories or treatment plans for use in further criminal acts or ransom demands in such breaches. UnitedHealth acknowledged for the first time that it paid ransom in attempt to stop the disclosure of stolen data.

Want to continue reading?
Become a Free PropertyCasualty360 Digital Reader

Your access to unlimited PropertyCasualty360 content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking insurance news and analysis, on-site and via our newsletters and custom alerts
  • Weekly Insurance Speak podcast featuring exclusive interviews with industry leaders
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the employee benefits and financial advisory markets on our other ALM sites, BenefitsPRO and ThinkAdvisor
NOT FOR REPRINT

© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.