OAK — OnChain Attack Knowledge

Worked example · 2024-02

Change Healthcare ransom payment — Bitcoin — 2024-02-21 to 2024-03-05

Loss
~$22M paid to ALPHV affiliate ("Notchy") in Bitcoin on or around March 1–3, 2024 for an intrusion that began February 21, 2024. UnitedHealth Group subsequently disclosed multi-billion-dollar U.S. healthcare-sector business-interruption impact (>$870M direct response cost in Q1 2024 reported earnings; multi-billion-dollar cumulative impact through year-end). The on-chain event documented here is the ransom payment and operator-side exit-scam reroute — the off-chain enterprise IT compromise of the Change Healthcare clearinghouse is out of OAK Tactic scope.
OAK Techniques observed
OAK-T5.008 (Ransomware Extortion Payment) — the extortion-payment leg of the ransomware kill chain; OAK-T7.002 (CEX Deposit-Address Layering) — primary downstream pattern observed at the affiliate-controlled wallet's off-ramp surface; OAK-T7.001 (Mixer-Routed Hop) — partial / earlier-stage component for the operator-side share post-reroute; OAK-T7.005 (Privacy-Chain Hops — the Bitcoin-to-Monero conversion leg in the operator-side off-ramp chain, the canonical post-2023 RaaS privacy-chain hop pattern per Chainalysis's privacy-chain cohort analysis); OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side methodology used by industry forensic providers to partition operator-side from affiliate-side flows during the exit-scam window.
Attribution
confirmed at the cluster-and-victim level. UnitedHealth Group CEO Andrew Witty confirmed in May 1, 2024 written testimony to the U.S. House Energy & Commerce Subcommittee on Oversight and Investigations that a ransom payment was made ([witty2024testimony]); HHS issued a public advisory characterising the incident as the largest U.S. healthcare-sector cyberattack on record ([hhs2024changehealthcare]); FBI / CISA / HHS prior advisories on ALPHV / BlackCat ([fbi2023blackcatdisruption], [cisa2023blackcatadvisory]) anchor the cluster attribution. The on-chain payment and exit-scam reroute were traced in close to real time by Chainalysis ([chainalysis2024alphvexit]) and TRM Labs ([trm2024changehealthcare]); Wired reporting ([wired2024changehealthcareransom]) consolidates the public-record facts. Per-flow attribution to specific successor venues for the operator-side share is inferred-strong per industry-forensic reconstruction.
OAK-Gnn
OAK-G10 ALPHV / BlackCat at the cluster level (operator + affiliate "Notchy"). Subsequent re-extortion of the same victim-data archive under successor-brand attribution is documented separately at examples/2024-04-change-healthcare-reextortion.md and attributes to OAK-G15 RansomHub.
Key teaching point
Change Healthcare is OAK's modern canonical case in the public record for real-time-traced-but-not-frozen ransomware payments to identified-but-non-OFAC-listed wallets. The detection chain ran cleanly: predicate event (2024-02-21) → industry-forensic per-hop tracing (T+0 to T+3 days from payment) → CEO testimony confirming payment (T+2 months from payment) → HHS sectoral advisory (T+0 from leak-site shutdown). What was missing in the chain was enforcement reach: no OFAC SDN listing on ALPHV-cluster wallets meant no regulated-venue cooperation could freeze the funds during the operator-side reroute window. Compared with the Bybit / THORChain laundering case (examples/2025-02-bybit-thorchain-laundering.md) where the same attribution-without-designation pattern recurred at much larger scale against a state-actor cluster, Change Healthcare establishes that the constraint is structural to the U.S. enforcement architecture rather than specific to any one cluster.

Summary

On February 21, 2024, the Change Healthcare clearinghouse — a UnitedHealth Group / Optum subsidiary processing approximately one in three U.S. medical claims — was encrypted by an ALPHV / BlackCat affiliate operating under the persona "Notchy." Initial access per HHS sectoral reporting and per UnitedHealth Group's subsequent disclosures was via an exposed Citrix portal lacking multi-factor authentication; the encryption deployment caused a multi-week clinical-and-financial-IT outage across U.S. pharmacies, hospitals, and revenue-cycle-management providers. UnitedHealth Group's parent disclosure cited at-least $870M in Q1 2024 direct response cost with multi-billion-dollar cumulative impact through year-end.

Per Wired's investigative reporting ([wired2024changehealthcareransom]), Chainalysis ([chainalysis2024alphvexit]), and TRM Labs ([trm2024changehealthcare]), an approximately $22M Bitcoin payment was sent on or around March 1–3, 2024 from a UnitedHealth-Group-controlled funding wallet to a Bitcoin address controlled by the ALPHV affiliate "Notchy." Within hours of receipt, the funds moved out of the affiliate's wallet under the ALPHV operator's payment-portal supervision and were redirected to operator-controlled wallets — the exit-scam event. The ALPHV operator subsequently shuttered the public ALPHV leak-site infrastructure on or around March 5, 2024, posting a fabricated FBI-seizure banner (visibly distinguishable from the real Operation Cronos LockBit takedown banner). Notchy publicly accused the ALPHV operator on the RAMP forum of stealing the affiliate share of the ~$22M payment, retained access to the exfiltrated victim-data archive, and re-monetised the data archive in April 2024 under the RansomHub successor brand (see linked re-extortion example).

For OAK's purposes, this is the canonical worked example of a real-time-traced ransomware payment that was not frozen. Industry forensic providers traced the payment within hours of confirmation; the operator-side exit-scam off-ramped a substantial fraction of those proceeds within days; no OFAC-SDN-listed-wallet enforcement action was available because no ALPHV-cluster wallet held an SDN listing at the time. The case is the load-bearing public-record counter-factual for the broader argument that on-chain visibility is necessary but not sufficient for ransomware-payment recovery — enforcement reach (administrative SDN designations on receiving wallets, regulated-CEX cooperation downstream, mixer-class designations on intermediating infrastructure) is the binding constraint.

Timeline (UTC)

When Event OAK ref
2024-02-21 ALPHV affiliate "Notchy" deploys ALPHV encryptor against Change Healthcare; multi-week U.S.-healthcare-sector IT outage begins (off-chain entry vector — Citrix portal without MFA) (off-chain entry)
2024-02-21 onward UnitedHealth Group / Optum incident response; HHS sectoral coordination begins (off-chain response)
2024-03-01 to 2024-03-03 Approximately $22M (350 BTC at then-prevailing price) paid from UnitedHealth-controlled funding wallet to Notchy-controlled Bitcoin address Ransom-payment event
2024-03-01 to 2024-03-03 (hours after receipt) Within hours of payment receipt, funds re-routed under ALPHV operator's payment-portal supervision out of Notchy's wallet to operator-controlled wallets — the exit-scam event T8.001 affiliate-vs-operator partition observable on-chain
2024-03-03 to 2024-03-05 ALPHV operator-side flow off-ramps through laundering rails consistent with broader Russian-language commercial-criminal off-ramp profile (Bitcoin-to-Monero conversion, non-KYC and lax-KYC CEX deposit-layering) T7.001 (partial) / T7.002 (primary)
2024-03-05 ALPHV operator shutters public leak-site infrastructure under fabricated FBI-seizure banner (operator-side wind-down)
2024-03-05 onward Notchy publicly accuses ALPHV operator on RAMP of stealing affiliate share; retains access to exfiltrated victim-data archive (affiliate dispute on public record)
2024-03-05 HHS public advisory issued ([hhs2024changehealthcare]) (sectoral-response coordination)
2024-04 Notchy re-monetises Change Healthcare data archive under RansomHub brand — see examples/2024-04-change-healthcare-reextortion.md (post-exit-scam re-extortion)
2024-05-01 UnitedHealth Group CEO Andrew Witty written testimony to House Energy & Commerce Subcommittee confirms ransom payment was made ([witty2024testimony]) (victim-side disclosure)

What defenders observed

  • Real-time on-chain trace, no real-time freeze. Chainalysis, TRM Labs, and other forensic providers traced the ~$22M Bitcoin payment within hours of receipt. The trace was made publicly available; the receiving wallet and downstream hops were known. Despite this, no on-chain freeze occurred — the ALPHV-cluster wallets held no OFAC SDN listing at the time of payment, and the operator-side reroute completed before any administrative or regulated-CEX-cooperation freeze could be staged.
  • Affiliate-vs-operator divergence visible on-chain. Within hours of payment receipt, the operator-side reroute partitioned the proceeds from Notchy's affiliate-controlled wallet to operator-controlled wallets. Industry forensic reconstruction (per [chainalysis2024alphvexit] and [trm2024changehealthcare]) shows the operator-side flow taking a different downstream path than the affiliate-side residual flow. The partition is observable on-chain and is the canonical worked case for OAK-T8.001 against a RaaS-terminal-phase event.
  • Counter-factual exposure window. The interval between cluster-attribution (FBI / CISA / HHS December 2023 ALPHV disruption advisories already in the public record) and OFAC-SDN-designation (which never occurred for ALPHV-cluster wallets) was the material exposure window during which the traced proceeds off-ramped under the operator's full control. OAK contributors writing future ransomware-payment examples should preserve this attribution-without-designation gap as a defender-side observation.
  • Sector-disclosure pressure tactic. UnitedHealth Group's initial disclosure tempo was constrained by litigation strategy and sector-coordination considerations; CEO confirmation of the ransom payment took until May 1, 2024 written testimony — approximately two months after the on-chain event was already publicly traced. The on-chain trace led the victim-side disclosure by approximately two months, a pattern that recurs across RaaS-payment events with publicly traceable Bitcoin payments and victims under SEC-or-HHS-disclosure-regime constraint.

What this example tells contributors writing future Technique pages

  • T7.002 affiliate-side off-ramp pattern is the post-2023 RaaS default. The Notchy-controlled receiving wallet's downstream off-ramp followed the canonical 2023-and-after pattern: deposit-address layering at non-KYC and lax-KYC venues, Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs, and the operator-side share rerouted to a different downstream rail than the affiliate-side residual flow. Contributors writing T7.002 examples for RaaS-attributed proceeds should expect this affiliate-vs-operator-partition pattern as the default, not as an exception.
  • T8.001 attribution methodology generalises to RaaS-terminal-phase events. The Common-Funder Cluster Reuse methodology used by Chainalysis, TRM Labs, and Mandiant to partition operator-side from affiliate-side wallet activity during the Change Healthcare exit-scam window applies cleanly to other RaaS-cluster-termination events (LockBit / Operation Cronos affiliate-cluster-reuse, Black Basta-internal-wind-down dispersal, etc.). Future T8.001 examples should preserve the affiliate-vs-operator distinction explicitly.
  • The "asset-freeze counter-factual" is a load-bearing OAK structural argument. Compared to OAK-G05 LockBit (Operation Cronos with same-day OFAC SDN designations of ten cryptocurrency-address identifiers) the Change Healthcare case produced no freeze surface despite confirmed-grade attribution at every layer except the OFAC-SDN-designation layer. The lesson for OAK content and downstream defenders / regulators / exchanges is that attribution without designation does not produce a freeze.

Public references

  • [witty2024testimony] — UnitedHealth Group CEO Andrew Witty written testimony to U.S. House Energy & Commerce Subcommittee on Oversight and Investigations, May 1, 2024 — confirms ransom payment was made. URL: https://energycommerce.house.gov/events/oversight-and-investigations-subcommittee-hearing-examining-the-change-healthcare-cyberattack
  • [wired2024changehealthcareransom] — Wired investigative reporting on the $22M BTC payment and the operator-side exit-scam dynamic. URL: https://www.wired.com/story/change-healthcare-ransom-payment-alphv/
  • [chainalysis2024alphvexit] — Chainalysis "Examining the Impact of Ransomware Disruptions: Qakbot, LockBit, and ALPHV-BlackCat" (2024) — covers ALPHV exit-scam dynamics and the Change Healthcare aftermath.
  • [trm2024changehealthcare] — TRM Labs forensic write-up of the Change Healthcare ransom payment, on-chain tracing, and operator-vs-affiliate divergence.
  • [hhs2024changehealthcare] — U.S. Department of Health and Human Services public advisory on the Change Healthcare cybersecurity incident.
  • [fbi2023blackcatdisruption] — FBI / DOJ December 19, 2023 announcement of the ALPHV / BlackCat disruption and FBI-issued decryptor; cluster-attribution upstream for this incident.
  • [cisa2023blackcatadvisory] — CISA / FBI joint cybersecurity advisory on ALPHV / BlackCat TTPs (December 2023 update).
  • [chainalysis2024changehealthcare] — Chainalysis on-chain trace of the Change Healthcare ransom payment (companion forensic write-up).

Discussion

Change Healthcare is OAK's modern canonical case in the public record for real-time-traced-but-not-frozen ransomware payments to identified-but-non-OFAC-listed wallets. The detection chain ran cleanly: predicate event (2024-02-21) → industry-forensic per-hop tracing (T+0 to T+3 days from payment) → CEO testimony confirming payment (T+2 months from payment) → HHS sectoral advisory (T+0 from leak-site shutdown). What was missing in the chain was enforcement reach: no OFAC SDN listing on ALPHV-cluster wallets meant no regulated-venue cooperation could freeze the funds during the operator-side reroute window. Compared with the Bybit / THORChain laundering case (examples/2025-02-bybit-thorchain-laundering.md) where the same attribution-without-designation pattern recurred at much larger scale against a state-actor cluster, Change Healthcare establishes that the constraint is structural to the U.S. enforcement architecture rather than specific to any one cluster.

The case also illustrates that the affiliate-vs-operator partition of victim-data archives may persist beyond the prior-cluster-termination event: Notchy retained access to the Change Healthcare data archive after the operator-side exit-scam diverted the original payment, and re-monetised the data archive in April 2024 under the RansomHub brand. Defender control-set design for ransomware response after Change Healthcare needs to assume that re-extortion under successor-brand attribution is part of the threat-actor toolkit, not a one-off. The companion example at examples/2024-04-change-healthcare-reextortion.md documents the re-extortion event under OAK-G15 RansomHub.

Techniques demonstrated (5)