/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A BlackCat ransomware gang website shows a takedown notice; the UK NCA denies involvement and experts suggest an exit scam after an alleged UnitedHealth payment

but is this really the end? Wall Street Journal : After the Change Healthcare attack, the US will relax some Medicare prescription rules and consider advance payments; some providers begin furloughing staff Mastodon: BrianKrebs / @briankrebs@infosec.exchange : If Change Healthcare indeed did pay $22 million, wouldn't they have to disclose that as a material issue in an SEC filing pretty soon? BrianKrebs / @briankrebs@infosec.exchange : I think probably the main reason Optum/Change Healthcare/UnitedHealth hasn't yet said it didn't pay $22 million as the data suggests is that they just don't want to see a bunch more headlines that start with “UnitedHealth Denies Claims....” Kevin Beaumont / @GossiTheDog@cyberplace.social : Some good reporting here - the NCA, who are listed on the alphabet portal as being involved in a takedown - say they were not involved in a takedown.  —  We'll see what the FBI says, but it looks like AlphV may well have done rug pull aka exit scam — stole their operator and affiliate's money and left their victims without decryption. … X: Fabian Wosar / @fwosar : Since people continue to fall for the ALPHV/BlackCat cover up: ALPHV/BlackCat did not get seized. They are exit scamming their affiliates. It is blatantly obvious when you check the source code of the new takedown notice. You will see code like this. [image] Lawrence Abrams / @lawrenceabrams : As expected, the FBI has “declined to comment” on BlackCat's seizure notices. This comes after the NCA has already stated they were not involved in any recent ALPHV disruption, but are listed on the banner. https://www.bleepingcomputer.com/ ... Fabian Wosar / @fwosar : An image URL like this is what Firefox and the Tor Browser create when you use the “Save page as” function to save a copy of a website to disk. This is what the logo URL in the real takedown notice looks like. [image] LinkedIn: Yossi Akselrud : I'd say this is national security level event.  —  Extremely curious how they got in, what needs to be hardened, we need to address and other cyber security/ infosec on a national level. … Adam Sewall : Any executive, cyber professional or IT Security Manager in Healthcare needs to be doing a hard assessment and making the case towards management of how to budget and deploy to mitigate such threats. … Andy Greenberg : AlphV, the hackers behind the ransomware attack on Change Healthcare that's snarled medical prescriptions nationwide, received a $22 million payment on March 1, visible on Bitcoin's blockchain. … Pramod John : It's time to end the monopolies because not only do we pay more, we end up with massive single points of failure. … Forums: r/hacking : BlackCat ransomware shuts down in exit scam, blames the “feds” r/nashville : Change Healthcare Pays $22 Million to Ransomware Group r/technews : Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment

Reuters

Context & Ripple Effects

Change Healthcare had already identified BlackCat as behind the attack disrupting pharmacy services, tying a criminal-group dispute directly to a critical healthcare technology outage. The new uncertainty is not merely whether the group’s site is offline, but whether its operators remain able—or willing—to honor obligations to victims and affiliates.

Reports of an alleged payment make the claimed shutdown consequential: a purported law-enforcement seizure and an operator exit scam imply very different risks for UnitedHealth, affected providers, and the group’s ransomware-as-a-service partners.

First-order effects

  • BlackCat affiliates may lose expected ransom proceeds and access to decryption support if the operators have withheld funds and abandoned the operation, as experts suggest.
  • UnitedHealth and Change Healthcare face added uncertainty over recovery and data-extortion exposure: a takedown banner does not establish that the attackers’ infrastructure, data, or leverage has been neutralized.

Second-order effects

  • Victims and incident-response teams must treat claimed takedowns as unverified operational signals, rather than assume that a payment or a seized-looking site ends an extortion event.
  • If the exit-scam account is accurate, it weakens affiliates’ trust in the BlackCat model and can push ransomware partners to seek groups with clearer payment and decryption arrangements.

Third-order effects

  • Ransomware-as-a-service becomes more fragile when operators can unilaterally retain proceeds, turning trust between criminals—not just technical capability—into a constraint on a group’s durability.
  • The episode underscores a persistent response problem: public-facing disruption notices and on-chain payment evidence can shape decisions before authorities or victims can conclusively establish who controls the operation.

The trend: Ransomware incidents are increasingly shaped by the instability of criminal service platforms, where affiliate incentives, payment disputes, and ambiguous takedown claims can prolong harm after an attack.

Discussion

  • @fwosar Fabian Wosar on x
    Since people continue to fall for the ALPHV/BlackCat cover up: ALPHV/BlackCat did not get seized. They are exit scamming their affiliates. It is blatantly obvious when you check the source code of the new takedown notice. You will see code like this. [image]
  • @lawrenceabrams Lawrence Abrams on x
    As expected, the FBI has “declined to comment” on BlackCat's seizure notices. This comes after the NCA has already stated they were not involved in any recent ALPHV disruption, but are listed on the banner. https://www.bleepingcomputer.com/ ...
  • @fwosar Fabian Wosar on x
    An image URL like this is what Firefox and the Tor Browser create when you use the “Save page as” function to save a copy of a website to disk. This is what the logo URL in the real takedown notice looks like. [image]
  • r/hacking r on reddit
    BlackCat ransomware shuts down in exit scam, blames the “feds”
  • r/nashville r on reddit
    Change Healthcare Pays $22 Million to Ransomware Group
  • r/technews r on reddit
    Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment