Worked example · 2024-02
Change Healthcare ransom payment — Bitcoin — 2024-02-21 to 2024-03-05
Summary
On February 21, 2024, the Change Healthcare clearinghouse — a UnitedHealth Group / Optum subsidiary processing approximately one in three U.S. medical claims — was encrypted by an ALPHV / BlackCat affiliate operating under the persona "Notchy." Initial access per HHS sectoral reporting and per UnitedHealth Group's subsequent disclosures was via an exposed Citrix portal lacking multi-factor authentication; the encryption deployment caused a multi-week clinical-and-financial-IT outage across U.S. pharmacies, hospitals, and revenue-cycle-management providers. UnitedHealth Group's parent disclosure cited at-least $870M in Q1 2024 direct response cost with multi-billion-dollar cumulative impact through year-end.
Per Wired's investigative reporting ([wired2024changehealthcareransom]), Chainalysis ([chainalysis2024alphvexit]), and TRM Labs ([trm2024changehealthcare]), an approximately $22M Bitcoin payment was sent on or around March 1–3, 2024 from a UnitedHealth-Group-controlled funding wallet to a Bitcoin address controlled by the ALPHV affiliate "Notchy." Within hours of receipt, the funds moved out of the affiliate's wallet under the ALPHV operator's payment-portal supervision and were redirected to operator-controlled wallets — the exit-scam event. The ALPHV operator subsequently shuttered the public ALPHV leak-site infrastructure on or around March 5, 2024, posting a fabricated FBI-seizure banner (visibly distinguishable from the real Operation Cronos LockBit takedown banner). Notchy publicly accused the ALPHV operator on the RAMP forum of stealing the affiliate share of the ~$22M payment, retained access to the exfiltrated victim-data archive, and re-monetised the data archive in April 2024 under the RansomHub successor brand (see linked re-extortion example).
For OAK's purposes, this is the canonical worked example of a real-time-traced ransomware payment that was not frozen. Industry forensic providers traced the payment within hours of confirmation; the operator-side exit-scam off-ramped a substantial fraction of those proceeds within days; no OFAC-SDN-listed-wallet enforcement action was available because no ALPHV-cluster wallet held an SDN listing at the time. The case is the load-bearing public-record counter-factual for the broader argument that on-chain visibility is necessary but not sufficient for ransomware-payment recovery — enforcement reach (administrative SDN designations on receiving wallets, regulated-CEX cooperation downstream, mixer-class designations on intermediating infrastructure) is the binding constraint.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2024-02-21 | ALPHV affiliate "Notchy" deploys ALPHV encryptor against Change Healthcare; multi-week U.S.-healthcare-sector IT outage begins (off-chain entry vector — Citrix portal without MFA) | (off-chain entry) |
| 2024-02-21 onward | UnitedHealth Group / Optum incident response; HHS sectoral coordination begins | (off-chain response) |
| 2024-03-01 to 2024-03-03 | Approximately $22M (350 BTC at then-prevailing price) paid from UnitedHealth-controlled funding wallet to Notchy-controlled Bitcoin address | Ransom-payment event |
| 2024-03-01 to 2024-03-03 (hours after receipt) | Within hours of payment receipt, funds re-routed under ALPHV operator's payment-portal supervision out of Notchy's wallet to operator-controlled wallets — the exit-scam event | T8.001 affiliate-vs-operator partition observable on-chain |
| 2024-03-03 to 2024-03-05 | ALPHV operator-side flow off-ramps through laundering rails consistent with broader Russian-language commercial-criminal off-ramp profile (Bitcoin-to-Monero conversion, non-KYC and lax-KYC CEX deposit-layering) | T7.001 (partial) / T7.002 (primary) |
| 2024-03-05 | ALPHV operator shutters public leak-site infrastructure under fabricated FBI-seizure banner | (operator-side wind-down) |
| 2024-03-05 onward | Notchy publicly accuses ALPHV operator on RAMP of stealing affiliate share; retains access to exfiltrated victim-data archive | (affiliate dispute on public record) |
| 2024-03-05 | HHS public advisory issued ([hhs2024changehealthcare]) |
(sectoral-response coordination) |
| 2024-04 | Notchy re-monetises Change Healthcare data archive under RansomHub brand — see examples/2024-04-change-healthcare-reextortion.md |
(post-exit-scam re-extortion) |
| 2024-05-01 | UnitedHealth Group CEO Andrew Witty written testimony to House Energy & Commerce Subcommittee confirms ransom payment was made ([witty2024testimony]) |
(victim-side disclosure) |
What defenders observed
- Real-time on-chain trace, no real-time freeze. Chainalysis, TRM Labs, and other forensic providers traced the ~$22M Bitcoin payment within hours of receipt. The trace was made publicly available; the receiving wallet and downstream hops were known. Despite this, no on-chain freeze occurred — the ALPHV-cluster wallets held no OFAC SDN listing at the time of payment, and the operator-side reroute completed before any administrative or regulated-CEX-cooperation freeze could be staged.
- Affiliate-vs-operator divergence visible on-chain. Within hours of payment receipt, the operator-side reroute partitioned the proceeds from Notchy's affiliate-controlled wallet to operator-controlled wallets. Industry forensic reconstruction (per
[chainalysis2024alphvexit]and[trm2024changehealthcare]) shows the operator-side flow taking a different downstream path than the affiliate-side residual flow. The partition is observable on-chain and is the canonical worked case for OAK-T8.001 against a RaaS-terminal-phase event. - Counter-factual exposure window. The interval between cluster-attribution (FBI / CISA / HHS December 2023 ALPHV disruption advisories already in the public record) and OFAC-SDN-designation (which never occurred for ALPHV-cluster wallets) was the material exposure window during which the traced proceeds off-ramped under the operator's full control. OAK contributors writing future ransomware-payment examples should preserve this attribution-without-designation gap as a defender-side observation.
- Sector-disclosure pressure tactic. UnitedHealth Group's initial disclosure tempo was constrained by litigation strategy and sector-coordination considerations; CEO confirmation of the ransom payment took until May 1, 2024 written testimony — approximately two months after the on-chain event was already publicly traced. The on-chain trace led the victim-side disclosure by approximately two months, a pattern that recurs across RaaS-payment events with publicly traceable Bitcoin payments and victims under SEC-or-HHS-disclosure-regime constraint.
What this example tells contributors writing future Technique pages
- T7.002 affiliate-side off-ramp pattern is the post-2023 RaaS default. The Notchy-controlled receiving wallet's downstream off-ramp followed the canonical 2023-and-after pattern: deposit-address layering at non-KYC and lax-KYC venues, Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs, and the operator-side share rerouted to a different downstream rail than the affiliate-side residual flow. Contributors writing T7.002 examples for RaaS-attributed proceeds should expect this affiliate-vs-operator-partition pattern as the default, not as an exception.
- T8.001 attribution methodology generalises to RaaS-terminal-phase events. The Common-Funder Cluster Reuse methodology used by Chainalysis, TRM Labs, and Mandiant to partition operator-side from affiliate-side wallet activity during the Change Healthcare exit-scam window applies cleanly to other RaaS-cluster-termination events (LockBit / Operation Cronos affiliate-cluster-reuse, Black Basta-internal-wind-down dispersal, etc.). Future T8.001 examples should preserve the affiliate-vs-operator distinction explicitly.
- The "asset-freeze counter-factual" is a load-bearing OAK structural argument. Compared to OAK-G05 LockBit (Operation Cronos with same-day OFAC SDN designations of ten cryptocurrency-address identifiers) the Change Healthcare case produced no freeze surface despite confirmed-grade attribution at every layer except the OFAC-SDN-designation layer. The lesson for OAK content and downstream defenders / regulators / exchanges is that attribution without designation does not produce a freeze.
Public references
[witty2024testimony]— UnitedHealth Group CEO Andrew Witty written testimony to U.S. House Energy & Commerce Subcommittee on Oversight and Investigations, May 1, 2024 — confirms ransom payment was made. URL: https://energycommerce.house.gov/events/oversight-and-investigations-subcommittee-hearing-examining-the-change-healthcare-cyberattack[wired2024changehealthcareransom]— Wired investigative reporting on the $22M BTC payment and the operator-side exit-scam dynamic. URL: https://www.wired.com/story/change-healthcare-ransom-payment-alphv/[chainalysis2024alphvexit]— Chainalysis "Examining the Impact of Ransomware Disruptions: Qakbot, LockBit, and ALPHV-BlackCat" (2024) — covers ALPHV exit-scam dynamics and the Change Healthcare aftermath.[trm2024changehealthcare]— TRM Labs forensic write-up of the Change Healthcare ransom payment, on-chain tracing, and operator-vs-affiliate divergence.[hhs2024changehealthcare]— U.S. Department of Health and Human Services public advisory on the Change Healthcare cybersecurity incident.[fbi2023blackcatdisruption]— FBI / DOJ December 19, 2023 announcement of the ALPHV / BlackCat disruption and FBI-issued decryptor; cluster-attribution upstream for this incident.[cisa2023blackcatadvisory]— CISA / FBI joint cybersecurity advisory on ALPHV / BlackCat TTPs (December 2023 update).[chainalysis2024changehealthcare]— Chainalysis on-chain trace of the Change Healthcare ransom payment (companion forensic write-up).
Discussion
Change Healthcare is OAK's modern canonical case in the public record for real-time-traced-but-not-frozen ransomware payments to identified-but-non-OFAC-listed wallets. The detection chain ran cleanly: predicate event (2024-02-21) → industry-forensic per-hop tracing (T+0 to T+3 days from payment) → CEO testimony confirming payment (T+2 months from payment) → HHS sectoral advisory (T+0 from leak-site shutdown). What was missing in the chain was enforcement reach: no OFAC SDN listing on ALPHV-cluster wallets meant no regulated-venue cooperation could freeze the funds during the operator-side reroute window. Compared with the Bybit / THORChain laundering case (examples/2025-02-bybit-thorchain-laundering.md) where the same attribution-without-designation pattern recurred at much larger scale against a state-actor cluster, Change Healthcare establishes that the constraint is structural to the U.S. enforcement architecture rather than specific to any one cluster.
The case also illustrates that the affiliate-vs-operator partition of victim-data archives may persist beyond the prior-cluster-termination event: Notchy retained access to the Change Healthcare data archive after the operator-side exit-scam diverted the original payment, and re-monetised the data archive in April 2024 under the RansomHub brand. Defender control-set design for ransomware response after Change Healthcare needs to assume that re-extortion under successor-brand attribution is part of the threat-actor toolkit, not a one-off. The companion example at examples/2024-04-change-healthcare-reextortion.md documents the re-extortion event under OAK-G15 RansomHub.