Worked example · 2024-04
Change Healthcare data-leak re-extortion — Bitcoin / RansomHub brand — 2024-04
Summary
In April 2024, the RansomHub leak site listed Change Healthcare as a victim and the affiliate operator under the persona "Notchy" — the same affiliate who ran the original ALPHV intrusion in February 2024 — re-extorted UnitedHealth Group / Optum by threatening to disclose the previously-exfiltrated victim-data archive (per the RansomHub leak-site claim, approximately 4 TB of patient and financial records). The event is the first publicly-documented case of post-exit-scam-affiliate-data-monetisation in the ransomware-and-data-extortion ecosystem: an affiliate retained access to a victim-data archive after the prior operator-brand's exit-scam diverted the original ransom payment, and re-monetised the archive under the successor RaaS brand.
For OAK's purposes, the case is the canonical worked example of RaaS-brand-rotation absorbing displaced affiliates from prior-cluster terminations and of the operator-pressure-tactic novelty that ransomware response runbooks now need to assume. The detection chain ran from the original ALPHV intrusion (Feb 21, 2024) → $22M Bitcoin payment (Mar 1–3, 2024) → ALPHV operator-side exit-scam (Mar 5, 2024) → RansomHub leak-site listing of Change Healthcare under Notchy (April 2024) → CISA AA24-242A joint advisory naming RansomHub as the dominant 2024 RaaS strain by victim-count and explicitly calling out the post-ALPHV affiliate-displacement dynamic (Aug 29, 2024).
The on-chain layer of this re-extortion event is materially less anchored than the predicate event: UnitedHealth Group did not publicly confirm a second payment with a separate dollar figure; the second extortion's ransom-payment trace (if any) is not on the public record at the granularity the predicate event is. What is on the public record is the cluster-continuity attestation — the attribution that Notchy's RansomHub-affiliate activity continues the wallet-funder-cluster signature observed during the ALPHV affiliate engagement, per industry-forensic tracking. The case anchors OAK-G15 at the cluster level and anchors the post-exit-scam-affiliate-data-monetisation operating-pattern novelty on the public record.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2024-02-21 to 2024-03-05 | Predicate event — see examples/2024-02-change-healthcare-ransom.md |
(predicate) |
| Late February 2024 | RansomHub leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums in February 2024, weeks before the early-March 2024 ALPHV operator-side exit-scam shutdown — the launch timing positioned RansomHub to absorb displaced ALPHV affiliates | (RansomHub launch context) |
| 2024-03-05 onward | Notchy publicly accuses ALPHV operator on RAMP of stealing affiliate share; retains access to exfiltrated Change Healthcare data archive | (affiliate dispute on public record) |
| April 2024 | RansomHub leak site lists Change Healthcare as a victim under Notchy's affiliate handle; demands a second ransom payment under threat of data-archive disclosure | Re-extortion event (operator-pressure-tactic novelty) |
| 2024-04-22 | Optum / UnitedHealth Group publicly acknowledges press-cycle pressure on the data-archive disclosure; HHS sectoral coordination continues | (sectoral response) |
| 2024-05-01 | Witty written testimony to House Energy & Commerce Subcommittee acknowledges payment was made ([witty2024testimony]) |
(victim-side disclosure) |
| 2024-08-29 | CISA / FBI / HHS / MS-ISAC joint cybersecurity advisory AA24-242A "StopRansomware: RansomHub Ransomware" issued; names RansomHub as dominant 2024 RaaS strain by victim-count and explicitly calls out the post-ALPHV affiliate-displacement dynamic ([cisa2024aa24242aransomhub]) |
Cluster attribution at confirmed |
What defenders observed
- Affiliate-data-archive persistence beyond operator-cluster termination. The most defender-relevant observation is that operator-cluster termination does not extinguish affiliate access to victim-data archives. Notchy retained 4 TB of Change Healthcare data after the ALPHV operator-side exit-scam diverted the original payment; the data archive was re-monetised under a successor RaaS brand within weeks. Defender control-set design for ransomware response now needs to assume that re-extortion under successor-brand attribution is part of the threat-actor toolkit and that prior-cluster-termination events do not close the data-disclosure-threat surface against victims.
- RaaS-brand-rotation as affiliate-displacement-absorber. RansomHub's launch timing (February 2024) positioned the brand to absorb displaced ALPHV affiliates immediately following the early-March 2024 ALPHV operator-side exit-scam. Per
[chainalysis2025ransomware]and[mandiant2024ransomhub], the post-March 2024 affiliate-onboarding tempo was unusually rapid for a new RaaS brand and is the canonical worked example of RaaS-affiliate-displacement-and-rapid-rebrand-absorption. The ~90 / 10 affiliate / operator split (per industry-forensic tracking) was deliberately calibrated to attract displaced ALPHV affiliates in the immediate post-exit-scam window. - Cluster-continuity attestation via wallet-funder-cluster reuse. The Notchy-as-RansomHub-affiliate attribution rests primarily on the persistence of Bitcoin-funder-cluster identity from ALPHV-affiliate wallets to RansomHub-affiliate wallets across the March-to-Q2 2024 displacement window — the canonical 2024 worked case for OAK-T8.001 against a RaaS-affiliate-rotation event. Forum-disclosure of the dispute on RAMP (Notchy's public accusation against the ALPHV operator) provides the off-chain corroboration; on-chain wallet-cluster reuse provides the forensic anchor.
What this example tells contributors writing future Technique pages
- T8.001 / T8.002 cluster-continuity attestation generalises to RaaS-affiliate-displacement events. Future RaaS-cluster-termination events (whether by law-enforcement seizure as with G05 / Operation Cronos, by operator-side exit-scam as with G10 / ALPHV, or by internal wind-down as with G11 / Black Basta and the BlackBastaLeaks event) should be expected to produce affiliate-displacement-absorption dynamics into successor brands. Forensic tracking via T8.001 wallet-funder-cluster-reuse and T8.002 cross-chain-operator-continuity is the canonical method for partitioning displaced-affiliate flows from successor-brand-operator flows.
- The post-exit-scam-affiliate-data-monetisation pattern is a sustained behaviour. Although Change Healthcare is the first publicly-documented case, the structural dynamic (an affiliate retains access to a victim-data archive after a prior-cluster-termination event and re-monetises under a successor brand) generalises to any RaaS-cluster-termination event where data-exfiltration-before-encryption is the standard double-extortion negotiation posture. Defenders should treat re-extortion-under-successor-brand as a default expectation, not as a one-off.
- The on-chain trace of re-extortion events is materially less anchored than predicate-event traces. Where predicate ransom-payment events leave a clean on-chain trace (the ~$22M payment from UnitedHealth-controlled funding wallet to Notchy was traced within hours), re-extortion events frequently leave a less-anchored trace because (a) the second payment may not be made, (b) the second payment if made is frequently negotiated and may use different funding wallets, and (c) the victim-side disclosure tempo may not separate first-payment from second-payment liability publicly. OAK contributors writing re-extortion examples should preserve this predicate-vs-re-extortion attribution-strength asymmetry explicitly.
Public references
[cisa2024aa24242aransomhub]— CISA / FBI / HHS / MS-ISAC joint cybersecurity advisory AA24-242A, "StopRansomware: RansomHub Ransomware," August 29, 2024. Cluster-attribution document for OAK-G15.[mandiant2024ransomhub]— Mandiant 2024 reporting on RansomHub as the largest 2024 RaaS strain by post-ALPHV-exit-scam affiliate-absorption volume.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; documents RansomHub cluster-share trajectory and the post-ALPHV-affiliate-displacement absorption pattern.[trm2024ransomhub]— TRM Labs forensic write-up of RansomHub on-chain payment tracing and the ALPHV-to-RansomHub affiliate-cluster-reuse continuity.[chainalysis2024alphvexit]— Chainalysis foundational organisational-continuity context for the ALPHV-to-RansomHub affiliate-displacement pattern.[witty2024testimony]— UnitedHealth Group CEO Andrew Witty written testimony to U.S. House Energy & Commerce Subcommittee, May 1, 2024.[hhs2024changehealthcare]— HHS public advisory on the Change Healthcare cybersecurity incident.
Discussion
The Change Healthcare re-extortion is the canonical worked example, on the public record, of post-exit-scam-affiliate-data-monetisation — an operating-pattern novelty that defender control-set design now needs to internalise. The structural dynamic (affiliate retains data archive across prior-cluster-termination, re-monetises under successor brand) is not specific to ALPHV / RansomHub: any RaaS-cluster-termination event with data-exfiltration-before-encryption as the standard negotiation posture produces the same exposure surface. The fact that RansomHub-the-brand was deliberately positioned to absorb displaced ALPHV affiliates at ~90 / 10 affiliate / operator split economics — the most affiliate-favourable in the major-RaaS-strain public record — accelerated the absorption tempo but did not invent the dynamic.
The case also illustrates an important attribution-strength asymmetry between predicate and re-extortion events. The predicate event (examples/2024-02-change-healthcare-ransom.md) has confirmed-grade cluster attribution and a clean on-chain trace of the ~$22M payment. The re-extortion event has confirmed-grade cluster attribution (RansomHub leak-site listing of Change Healthcare under Notchy is on the public record) but inferred-strong-grade on-chain attribution at the per-flow level (no public confirmation of a second payment with a separate dollar figure). OAK contributors writing re-extortion examples should be explicit about which layer of attribution-strength applies to which factual claim, and should not project predicate-event confirmed-grade attribution onto re-extortion-event flow-level claims that are inferred-strong only.