Dark Perimeter: Real Breaches, Real Stakes
Every major cyberattack has a story behind it. A vulnerability no one patched. A phishing email someone clicked. A nation-state with a motive. Dark Perimeter goes beyond the headlines to explore the true stories of the hacks, breaches, and cyber operations that shaped history - told in narrative form for security professionals and curious minds alike. No guests, no panels, no filler. Just the story.
Dark Perimeter: Real Breaches, Real Stakes
The Breach Files: Nine Days
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
On February 12, 2024, someone signed into a Citrix remote-access portal at Change Healthcare with a valid username and a valid password. Nine days later, the largest medical claims clearinghouse in the United States stopped, and with it the revenue cycle of hospitals, pharmacies, and physician practices across the country.
Cole Drayden, Dr. Elliott Vance, and Marcus Hale open the Change Healthcare file: the nine-day dwell that most retellings erase, the MFA gap that UnitedHealth's own policy prohibited, the pre-acquisition backups that encrypted alongside production, and the $22 million ransom that bought nothing because the criminals defrauded each other.
Also: why 192.7 million is the right number and "one in three Americans" was only the early estimate, why the Justice Department's 2022 antitrust case and the 2024 resilience failure turned out to be the same argument in different vocabulary, and what a security director with a budget and no leverage should actually do about it.
Dark Perimeter: True Cybersecurity Stories.
On the twelfth of February 2024, someone logged into a remote access portal at a company most Americans had never heard of. They used a valid username and a valid password. Nothing broke, no alarm fired. From the portal's point of view, an authorized person had come to work. Nine days later, a third of the American healthcare payment system stopped functioning. I want to be careful with that sentence, because the version of this story that circulates is usually wrong in a specific and instructive way. People remember the 21st of February. That is the day the ransomware detonated, the day the shutdown began, the day it became news. The twelfth is the day that actually matters. And the nine days in between are the entire lesson. This is Dark Perimeter. I'm Cole Draden. With me are Dr. Elliot Vance and Marcus Hale, and today we are opening the Change Healthcare file.
SPEAKER_01The scale is worth establishing before the mechanism, because the mechanism is almost boring and the scale is not. Change Healthcare is a clearinghouse. When your doctor submits a claim to your insurer, that claim does not travel directly. It goes through an intermediary that translates, validates, roots, and reconciles it. Change was one of the largest such intermediaries in the country. In 2022, United Health Group acquired it for roughly $13 billion over the objection of the Department of Justice, which sued to block the deal and lost. The final accounting, and this took 18 months to settle, is that the protected health information of approximately 192.7 million people was exposed. That is the largest healthcare data breach in United States history. It is roughly 57% of the country. The Office for Civil Rights described it as being of unprecedented magnitude, which is not language regulators use casually.
SPEAKER_02And here's what I want practitioners to sit with. Andrew Whitdy, United Health's chief executive, testified under oath about the entry point. His written testimony to the Senate Finance Committee says the criminals used compromised credentials to remotely access a change healthcare citrics portal. And then this sentence the portal did not have multi-factor authentication. That is it. That is the whole vector. No zero day, no supply chain implant, no nation-state trade craft. Despite the fact that United Health's own first securities filing described a suspected nation-state associated threat actor, which turned out to be wrong. It was a criminal ransomware affiliate. I have sat in enough incident reviews to know how that Citrix portal happened. Nobody decided to leave MFA off it. United Health had a policy requiring MFA on all external facing systems. The portal was simply not covered by the thing that enforced the policy, and no process ever reconciled the two lists.
SPEAKER_00Marcus. Whitdy was asked about that directly in the House hearing. His answer was that they were continuing to investigate exactly why MFA was not on that particular service. And then it clearly was not.
SPEAKER_02Right. And as far as I can tell, no authoritative public explanation ever followed, which is the part that should make you uncomfortable, not comfortable. If your chief executive were put under oath and asked why one specific internet-facing server lacked to control your own policy mandates, and the honest answer was that you are still looking into it, then you have this gap. Most organizations do. Policy coverage and policy enforcement are different inventories, and almost nobody reconciles them continuously.
SPEAKER_01Let me walk the nine days, because the shape of it is the shape of nearly every modern intrusion. February 12th, initial access through the portal, then lateral movement. According to information Senator Wyden's office received in briefings from the company, the attackers reached the Microsoft Active Directory environment and created privileged administrative accounts of their own. Data was exfiltrated during this window. We do not know precisely when exfiltration began or ended, and I want to flag that rather than fill it in. February 21st, ransomware deployed. United Health detects the intrusion and makes a decision that credit where it is due worked. It proactively disconnects change healthcare from every system it touches. The blast radius stayed inside change. The rest of United Health kept running.
SPEAKER_02Pre-acquisition legacy infrastructure. He also described technology in that estate dating back 40 years. So the backups were in the same trust zone as production. They encrypted with everything else. That is why recovery took what it took.
SPEAKER_00Let's talk about what recovery looked like from the outside, because this is where the story stops being about a company and starts being about people. Pharmacies could not process claims electronically. Military and TRICARE pharmacies were the worst hit and the slowest to recover. Beneficiaries were told to pay the full retail cost of prescriptions up front and file for reimbursement later, which for some drugs means thousands of dollars they did not have. Base pharmacies were triaging, urgent prescriptions first, routine prescriptions after, extended wait times due to the system outage. Hospitals could not bill. The American Hospital Association surveyed about a thousand of them in the second week of March. Ninety-four percent reported financial impact. More than half called it significant or serious. Of the hospitals reporting cash flow effects, around 60% said they were losing more than a million dollars a day. And 74% reported direct impacts on patient care. Senator Wyden described small practices, stuffing envelopes with paper claims. Whittier to his credit, used the same register. The rural family medicine practice, struggling to make payroll.
SPEAKER_01United Health ultimately extended something on the order of $9 billion in advances and interest-free loans to keep providers solvent while the rail was down. Roughly a third of that lending went to Safety Net hospitals and federally qualified health centers. In 2025, the company began pressing providers to repay those loans, which generated its own round of unhappiness. Full restoration is the detail most retellings get wrong. Pharmacy claims were back to 99% of pre-incident volume by March 7th. The electronic payments platform came back March 15th. Those are genuinely fast. But the clearinghouse itself was not restored until November of 2024, roughly nine months after the attack, and several services were still not fully restored at that point.
SPEAKER_00Because it says something about ransom payment that no policy document says as well.
SPEAKER_02United Health paid $22 million in Bitcoin. Whitti confirmed the amount to the House Committee on May 1st, and he owned it personally. As chief executive officer, the decision to pay a ransom was mine. This was one of the hardest decisions I've ever had to make. They paid for a promise that the stolen data would be deleted.
SPEAKER_01What they did not know and could not have modeled is that the ransomware group they were paying was about to defraud its own contractor. Ransomware as a service works on a revenue split. An affiliate does the actual intrusion and takes the majority share, typically 70 or 80%. The affiliate on this operation used the handle Notchie. The payment landed in a wallet blockchain researchers had already attributed to ALPHV around the 1st of March. ALPHV kept all of it and suspended Notchie's account. So on March 3rd, Notchie went public on a Russian-language criminal forum with the transaction receipts and a complaint. His post, and I am quoting the translation, after receiving the payment, ALPHV team decide to suspend our account and keep lying and delaying when we contacted ALPHV admin. Sadly for Change Healthcare, their data is still with us.
SPEAKER_00ALPHV's response was almost comedic. They posted a law enforcement seizure banner on their own leak site, claiming the FBI, Europol, and the National Crime Agency had taken them down. It was a copy of the real notice from the previous December served off a Python development web server. A researcher who looked at it called the implementation lazy. Europol said it had no involvement. The National Crime Agency declined any involvement. ALPHV's administrators told their own affiliates that the Fed screwed us over, set their contact status to GG, and offered their source code for $5 million.
SPEAKER_02And then in April, the data came back. A group called Ransom Hub listed Change Healthcare claimed four terabytes and started a countdown to sell it. They published samples, billing files, insurance records, medical information contracts. I want to be precise here because this gets garbled constantly. RansomHub is not ALPHV rebranded. Simon Tech assessed with high confidence that Ransom Hub is a rebrand of Knight Ransomware, with no direct link established to ALPHV. What is supported is that the affiliate moved. Same operator, different brand. And there is no confirmation that United Health paid a second time. The likeliest read is simply that the internal dispute left the data in limbo.
SPEAKER_00So $22 million bought nothing. Not because the negotiation was handled badly, not because the decryptor failed. It bought nothing because two criminals disagreed about how to split the money, and the one holding the data was the one who got stiffed. Asked whether he could affirm that the attackers had retained no copies, Whittier's answer was I cannot affirmatively say that.
SPEAKER_01Which is the honest answer, and it is the answer for every ransom payment ever made. Paying purchases a promise from someone whose business model is breaking promises. The change file just supplies an unusually vivid demonstration of a failure mode that is not in anyone's threat model, the counterparty's internal compensation dispute.
SPEAKER_00Let me ask you both for the takeaway. Marcus, you first, and I want the version you would say to a security director with a budget and no leverage.
SPEAKER_02Two things. First, reconcile your MFA coverage continuously, not annually. Every internet-facing authentication endpoint matched against the enforcement inventory with the delta reported as a metric someone owns. The gap is never a decision. It is always a system that nobody remembered to add. And understand that MFA presence is necessary and not sufficient. The federal advisory on this group specifically documents them using EvilGink 2 to harvest credentials and session cookies straight through MFA. You want phishing resistant factors and session binding, not a checkbox. Second. And this is the one that actually determined the outcome here. Your backups have to be outside the trust zone they protect. If domain compromise reaches your backup infrastructure, you do not have backups. You have a second copy of the hostage. Validate that with a restore test, not an attestation.
SPEAKER_01Mine is about concentration, and it is uncomfortable because it is mostly not solvable at your desk. By United Health's own accounting, change represented about 6% of all healthcare payments nationally. 6%. And the degradation of that one intermediary financially damaged 94% of surveyed hospitals, which tells you the percentage metric is measuring the wrong thing. Clearinghouse dependency is serial and non-substitutable. If the rail is down, it is not 6% of your revenue cycle that stops, it is all of it. And the alternative was frequently foreclosed by contract. Senator Wyden's office found that exclusive arrangements prevented more than a third of providers from switching clearinghouses at all.
SPEAKER_00Which brings the antitrust thread back around in a way I did not expect when I started reading this file.
SPEAKER_01It does, and I think it is the most interesting thing in the case. The Justice Department sued to block this acquisition in February 2022, calling change a critical data highway and alleging it processed roughly half of all Americans' health insurance claims. DOJ lost, then dropped its appeal. The competition argument and the cyber resilience argument turned out to be the same argument in different vocabulary. The concentration the Justice Department called an antitrust harm is precisely what allowed one missing authentication control to become a national outage. Nobody at that trial was talking about MFA. They were describing the conditions under which its absence would matter this much.
SPEAKER_02Which is why the practitioner version of that lesson lands in contract language. If consolidation is going to move your risk onto a shared rail you cannot audit, then due diligence rights, resilience commitments, and a tested manual fallback belong in the agreement because the market is not going to hand you a second option. Know your manual processing burn rate in days, not as a tabletop exercise, as a number your CFO already has.
SPEAKER_00One more thread before we close, and it is small, but it costs organizations real money. United Health's first securities filing said suspected nation-state associated threat actor. It was a criminal affiliate. That correction came later and quietly. Attribution in hour twenty-four shapes disclosure posture, insurance treatment, law enforcement engagement, and internal narrative for months afterward. Say what you know. Say when you will know more. Resist the instinct to reach for the framing that makes the intrusion sound unavoidable. Because the through line of this file is that it was avoidable, and the cost of it not being avoided was three point zero nine billion dollars to a company that had told the market, nine days after detection, that the incident was not reasonably likely to have a material impact on its financial condition. The first estimate was around one point four billion. Then two point four. The final number was three point zero nine billion. That escalation is its own lesson about how long it takes to know the size of a hole.
SPEAKER_01And the entry point was a login prompt.
SPEAKER_00The entry point was a login prompt. Nine days of quiet in the middle of February at a company whose name most of the 192 million affected people had still never heard when the letters arrived. This is dark perimeter.