OAK — OnChain Attack Knowledge

Worked example · 2024-04

Change Healthcare data-leak re-extortion — Bitcoin / RansomHub brand — 2024-04

Loss
ransom amount for the second extortion event not publicly disclosed at full granularity; Notchy listed Change Healthcare on the RansomHub leak site in April 2024 demanding a second payment under threat of disclosure of the previously exfiltrated victim-data archive (4 TB of patient and financial records per the RansomHub leak-site claim, including PII, billing, and clinical data). Per multiple industry-forensic write-ups, the second-payment outcome was not publicly confirmed by UnitedHealth Group at the time; the data archive was subsequently leaked in part on the RansomHub leak-site press cycle. Witty's May 1, 2024 testimony ([witty2024testimony]) acknowledged a payment was made (with phrasing that did not partition first-payment from second-payment liability publicly) but did not provide separate dollar figures.
OAK Techniques observed
OAK-T5.008 (Ransomware Extortion Payment) — the extortion-payment leg of the ransomware kill chain; OAK-T7.002 (CEX Deposit-Address Layering) — to the extent any second payment was made, the off-ramp pattern continues the canonical post-2023 RaaS affiliate layering profile; OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side methodology used by industry forensic providers to attest the Notchy-as-RansomHub-affiliate continuity across the ALPHV-to-RansomHub displacement window; OAK-T8.002 (Cross-Chain Operator Continuity) — observed in Notchy's persona-and-wallet-cluster reuse on RAMP and the RansomHub leak-site infrastructure.
Attribution
confirmed at the cluster level (the RansomHub leak-site post listing Change Healthcare is on the public record and was widely reported in April 2024); attribution of the Notchy-as-RansomHub-affiliate continuity is inferred-strong per industry-forensic reconstruction (per [chainalysis2025ransomware], [trm2024ransomhub], [mandiant2024ransomhub], and [cisa2024aa24242aransomhub]). The RansomHub-as-ALPHV-displacement-absorber attribution is confirmed at the cluster level via the August 29, 2024 CISA AA24-242A joint advisory.
OAK-Gnn
OAK-G15 RansomHub at the cluster level. Predicate event under OAK-G10 ALPHV / BlackCat is documented separately at examples/2024-02-change-healthcare-ransom.md.
Predicate
examples/2024-02-change-healthcare-ransom.md — the original ALPHV-affiliate intrusion and ~$22M Bitcoin payment, followed by the operator-side exit-scam in early March 2024 that left Notchy with affiliate access to the exfiltrated data archive.
Key teaching point
The Change Healthcare re-extortion is the canonical worked example, on the public record, of post-exit-scam-affiliate-data-monetisation — an operating-pattern novelty that defender control-set design now needs to internalise. The structural dynamic (affiliate retains data archive across prior-cluster-termination, re-monetises under successor brand) is not specific to ALPHV / RansomHub: any RaaS-cluster-termination event with data-exfiltration-before-encryption as the standard negotiation posture produces the same exposure surface. The fact that RansomHub-the-brand was deliberately positioned to absorb displaced ALPHV affiliates at ~90 / 10 affiliate / operator split economics — the most affiliate-favourable in the major-RaaS-strain public record — accelerated the absorption tempo but did not invent the dynamic.

Summary

In April 2024, the RansomHub leak site listed Change Healthcare as a victim and the affiliate operator under the persona "Notchy" — the same affiliate who ran the original ALPHV intrusion in February 2024 — re-extorted UnitedHealth Group / Optum by threatening to disclose the previously-exfiltrated victim-data archive (per the RansomHub leak-site claim, approximately 4 TB of patient and financial records). The event is the first publicly-documented case of post-exit-scam-affiliate-data-monetisation in the ransomware-and-data-extortion ecosystem: an affiliate retained access to a victim-data archive after the prior operator-brand's exit-scam diverted the original ransom payment, and re-monetised the archive under the successor RaaS brand.

For OAK's purposes, the case is the canonical worked example of RaaS-brand-rotation absorbing displaced affiliates from prior-cluster terminations and of the operator-pressure-tactic novelty that ransomware response runbooks now need to assume. The detection chain ran from the original ALPHV intrusion (Feb 21, 2024) → $22M Bitcoin payment (Mar 1–3, 2024) → ALPHV operator-side exit-scam (Mar 5, 2024) → RansomHub leak-site listing of Change Healthcare under Notchy (April 2024) → CISA AA24-242A joint advisory naming RansomHub as the dominant 2024 RaaS strain by victim-count and explicitly calling out the post-ALPHV affiliate-displacement dynamic (Aug 29, 2024).

The on-chain layer of this re-extortion event is materially less anchored than the predicate event: UnitedHealth Group did not publicly confirm a second payment with a separate dollar figure; the second extortion's ransom-payment trace (if any) is not on the public record at the granularity the predicate event is. What is on the public record is the cluster-continuity attestation — the attribution that Notchy's RansomHub-affiliate activity continues the wallet-funder-cluster signature observed during the ALPHV affiliate engagement, per industry-forensic tracking. The case anchors OAK-G15 at the cluster level and anchors the post-exit-scam-affiliate-data-monetisation operating-pattern novelty on the public record.

Timeline (UTC)

When Event OAK ref
2024-02-21 to 2024-03-05 Predicate event — see examples/2024-02-change-healthcare-ransom.md (predicate)
Late February 2024 RansomHub leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums in February 2024, weeks before the early-March 2024 ALPHV operator-side exit-scam shutdown — the launch timing positioned RansomHub to absorb displaced ALPHV affiliates (RansomHub launch context)
2024-03-05 onward Notchy publicly accuses ALPHV operator on RAMP of stealing affiliate share; retains access to exfiltrated Change Healthcare data archive (affiliate dispute on public record)
April 2024 RansomHub leak site lists Change Healthcare as a victim under Notchy's affiliate handle; demands a second ransom payment under threat of data-archive disclosure Re-extortion event (operator-pressure-tactic novelty)
2024-04-22 Optum / UnitedHealth Group publicly acknowledges press-cycle pressure on the data-archive disclosure; HHS sectoral coordination continues (sectoral response)
2024-05-01 Witty written testimony to House Energy & Commerce Subcommittee acknowledges payment was made ([witty2024testimony]) (victim-side disclosure)
2024-08-29 CISA / FBI / HHS / MS-ISAC joint cybersecurity advisory AA24-242A "StopRansomware: RansomHub Ransomware" issued; names RansomHub as dominant 2024 RaaS strain by victim-count and explicitly calls out the post-ALPHV affiliate-displacement dynamic ([cisa2024aa24242aransomhub]) Cluster attribution at confirmed

What defenders observed

  • Affiliate-data-archive persistence beyond operator-cluster termination. The most defender-relevant observation is that operator-cluster termination does not extinguish affiliate access to victim-data archives. Notchy retained 4 TB of Change Healthcare data after the ALPHV operator-side exit-scam diverted the original payment; the data archive was re-monetised under a successor RaaS brand within weeks. Defender control-set design for ransomware response now needs to assume that re-extortion under successor-brand attribution is part of the threat-actor toolkit and that prior-cluster-termination events do not close the data-disclosure-threat surface against victims.
  • RaaS-brand-rotation as affiliate-displacement-absorber. RansomHub's launch timing (February 2024) positioned the brand to absorb displaced ALPHV affiliates immediately following the early-March 2024 ALPHV operator-side exit-scam. Per [chainalysis2025ransomware] and [mandiant2024ransomhub], the post-March 2024 affiliate-onboarding tempo was unusually rapid for a new RaaS brand and is the canonical worked example of RaaS-affiliate-displacement-and-rapid-rebrand-absorption. The ~90 / 10 affiliate / operator split (per industry-forensic tracking) was deliberately calibrated to attract displaced ALPHV affiliates in the immediate post-exit-scam window.
  • Cluster-continuity attestation via wallet-funder-cluster reuse. The Notchy-as-RansomHub-affiliate attribution rests primarily on the persistence of Bitcoin-funder-cluster identity from ALPHV-affiliate wallets to RansomHub-affiliate wallets across the March-to-Q2 2024 displacement window — the canonical 2024 worked case for OAK-T8.001 against a RaaS-affiliate-rotation event. Forum-disclosure of the dispute on RAMP (Notchy's public accusation against the ALPHV operator) provides the off-chain corroboration; on-chain wallet-cluster reuse provides the forensic anchor.

What this example tells contributors writing future Technique pages

  • T8.001 / T8.002 cluster-continuity attestation generalises to RaaS-affiliate-displacement events. Future RaaS-cluster-termination events (whether by law-enforcement seizure as with G05 / Operation Cronos, by operator-side exit-scam as with G10 / ALPHV, or by internal wind-down as with G11 / Black Basta and the BlackBastaLeaks event) should be expected to produce affiliate-displacement-absorption dynamics into successor brands. Forensic tracking via T8.001 wallet-funder-cluster-reuse and T8.002 cross-chain-operator-continuity is the canonical method for partitioning displaced-affiliate flows from successor-brand-operator flows.
  • The post-exit-scam-affiliate-data-monetisation pattern is a sustained behaviour. Although Change Healthcare is the first publicly-documented case, the structural dynamic (an affiliate retains access to a victim-data archive after a prior-cluster-termination event and re-monetises under a successor brand) generalises to any RaaS-cluster-termination event where data-exfiltration-before-encryption is the standard double-extortion negotiation posture. Defenders should treat re-extortion-under-successor-brand as a default expectation, not as a one-off.
  • The on-chain trace of re-extortion events is materially less anchored than predicate-event traces. Where predicate ransom-payment events leave a clean on-chain trace (the ~$22M payment from UnitedHealth-controlled funding wallet to Notchy was traced within hours), re-extortion events frequently leave a less-anchored trace because (a) the second payment may not be made, (b) the second payment if made is frequently negotiated and may use different funding wallets, and (c) the victim-side disclosure tempo may not separate first-payment from second-payment liability publicly. OAK contributors writing re-extortion examples should preserve this predicate-vs-re-extortion attribution-strength asymmetry explicitly.

Public references

  • [cisa2024aa24242aransomhub] — CISA / FBI / HHS / MS-ISAC joint cybersecurity advisory AA24-242A, "StopRansomware: RansomHub Ransomware," August 29, 2024. Cluster-attribution document for OAK-G15.
  • [mandiant2024ransomhub] — Mandiant 2024 reporting on RansomHub as the largest 2024 RaaS strain by post-ALPHV-exit-scam affiliate-absorption volume.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; documents RansomHub cluster-share trajectory and the post-ALPHV-affiliate-displacement absorption pattern.
  • [trm2024ransomhub] — TRM Labs forensic write-up of RansomHub on-chain payment tracing and the ALPHV-to-RansomHub affiliate-cluster-reuse continuity.
  • [chainalysis2024alphvexit] — Chainalysis foundational organisational-continuity context for the ALPHV-to-RansomHub affiliate-displacement pattern.
  • [witty2024testimony] — UnitedHealth Group CEO Andrew Witty written testimony to U.S. House Energy & Commerce Subcommittee, May 1, 2024.
  • [hhs2024changehealthcare] — HHS public advisory on the Change Healthcare cybersecurity incident.

Discussion

The Change Healthcare re-extortion is the canonical worked example, on the public record, of post-exit-scam-affiliate-data-monetisation — an operating-pattern novelty that defender control-set design now needs to internalise. The structural dynamic (affiliate retains data archive across prior-cluster-termination, re-monetises under successor brand) is not specific to ALPHV / RansomHub: any RaaS-cluster-termination event with data-exfiltration-before-encryption as the standard negotiation posture produces the same exposure surface. The fact that RansomHub-the-brand was deliberately positioned to absorb displaced ALPHV affiliates at ~90 / 10 affiliate / operator split economics — the most affiliate-favourable in the major-RaaS-strain public record — accelerated the absorption tempo but did not invent the dynamic.

The case also illustrates an important attribution-strength asymmetry between predicate and re-extortion events. The predicate event (examples/2024-02-change-healthcare-ransom.md) has confirmed-grade cluster attribution and a clean on-chain trace of the ~$22M payment. The re-extortion event has confirmed-grade cluster attribution (RansomHub leak-site listing of Change Healthcare under Notchy is on the public record) but inferred-strong-grade on-chain attribution at the per-flow level (no public confirmation of a second payment with a separate dollar figure). OAK contributors writing re-extortion examples should be explicit about which layer of attribution-strength applies to which factual claim, and should not project predicate-event confirmed-grade attribution onto re-extortion-event flow-level claims that are inferred-strong only.

Techniques demonstrated (4)