---
title: UnitedHealth Group’s Optum Subsidiary disrupted by Cyberattack | ARIA Cybersecurity
description: A major cyberattack has just hit the systems of a subsidiary of US health insurance giant, UnitedHealth. The attack is causing widespread disruption in the healthcare sector.
image: https://blog.ariacybersecurity.com/hubfs/shutterstock_578912143.jpg
---

[![ARIA Cybersecurity](https://www.ariacybersecurity.com/wp-content/themes/cspi/library/images/Aria_Logos_2025_RGB_Primary%20Horizontal-1.png)](https://www.ariacybersecurity.com/)

Toggle navigation

Search

- [About Us](https://www.ariacybersecurity.com/about-us/) 
    - [Events](https://www.ariacybersecurity.com/about-us/events/)
    - [Careers](https://www.ariacybersecurity.com/about-us/careers/)
    - [ISO 9001:2015 Certification](https://www.ariacybersecurity.com/about-us/iso-90012015-certification/)
    - [Industry Awards and Recognition](https://www.ariacybersecurity.com/about-us/industry-awards-and-recognition/)
    - [Location](https://www.ariacybersecurity.com/about-us/locations/)
- [Support](https://www.ariacybersecurity.com/support/)
- Contact Us
- [1-800-325-3110](tel:8003253110)
- [REQUEST A DEMO](https://info.ariacybersecurity.com/azt-demo)

- Cybersecurity Products 
    - [ARIA AZT PROTECT](https://www.ariacybersecurity.com/aria-azt-protect/)
    - [ARIA ADR](https://www.ariacybersecurity.com/cybersecurity-products/aria-sds-advanced-detection-and-response/)
    - [Cybersecurity Partners](https://www.ariacybersecurity.com/cybersecurity-products/cybersecurity-partners/)
- MSSP & OEM Solutions 
    - [MSSP Solutions](https://www.ariacybersecurity.com/mssp-solutions/)
    - [OEM Solutions](https://www.ariacybersecurity.com/oem-solutions/)
- [Blog](https://blog.ariacybersecurity.com/blog)
- [News](https://www.ariacybersecurity.com/about-us/news/)
- [Resources](https://www.ariacybersecurity.com/about-us/resources/)

 read

 February 29, 2024

# UnitedHealth Group’s Optum Subsidiary disrupted by Cyberattack putting critical patient needs at risk.

![](https://blog.ariacybersecurity.com/hubfs/shutterstock_578912143.jpg)

A major cyberattack has just hit the systems of a subsidiary of US health insurance giant, UnitedHealth. In an [SEC filing,](https://www.sec.gov/ixviewer/ix.html?doc=/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm) UnitedHealth said that it suspected a “nation-state associated cyber security threat actor” of gaining access to Change Healthcare, part of its Optum subsidiary and one of the largest prescription processors in the US, forcing it offline.

 

The attack is causing widespread disruption in the healthcare sector, preventing patients from using their health insurance to pay for prescriptions as healthcare providers disconnect from Optum.

 

“I believe it’s our Colonial Pipeline moment in healthcare,” Carter Groome, chief executive of First Health Advisory, told the [Wall Street Journal.](https://www.wsj.com/articles/hospitals-urged-to-disconnect-from-unitedhealths-hacked-pharmacy-unit-11c9691e)

 

UnitedHealth hasn’t confirmed the exact nature of the attack. But [reports](https://www.scmagazine.com/news/exclusive-cyberattack-on-change-healthcare-was-an-exploit-of-the-connectwise-flaw) suggest it could be caused by a strain of the LockBit malware used to exploit vulnerabilities in the ConnectWise ScreenConnect remote software application. This vulnerability ([CVE-2024-1709](https://www.cisa.gov/news-events/alerts/2024/02/22/cisa-adds-one-known-exploited-connectwise-vulnerability-cve-2024-1709-catalog)) was publicised just a few days previously and given a severity rating of “critical.”

 

If this proves to be the source of the UnitedHealth attack, it means hackers have moved quickly to exploit the vulnerability – before companies have had time to patch against it.

 

The ability of a nation-state actor to use the highly sophisticated LockBit malware to bring down a major healthcare provider highlights the major risks facing US critical infrastructure.

 

It’s also another example of an attack that would’ve been prevented by our AZT PROTECT solution. It uses a patented approach to lock down critical applications from exploitation, while blocking the execution of zero-day malware, and automatically stopping the sophisticated techniques used by the most advanced nation-state sponsored attackers.

 

To see how AZT PROTECT can safeguard your critical infrastructure from this type of attack [request a demo](https://info.ariacybersecurity.com/azt-demo)

 Tags: [cyber attack](https://blog.ariacybersecurity.com/blog/tag/cyber-attack), [data breach](https://blog.ariacybersecurity.com/blog/tag/data-breach), [cybersecurity](https://blog.ariacybersecurity.com/blog/tag/cybersecurity), [data protection](https://blog.ariacybersecurity.com/blog/tag/data-protection)

### Related Articles

<https://blog.ariacybersecurity.com/blog/defending-water-ot-with-azt-protect>

## [Securing the Tap: Defending Water OT with AZT PROTECT and Perimeter Defenses](https://blog.ariacybersecurity.com/blog/defending-water-ot-with-azt-protect)

*( read )*

 Topics: [cyber attack](https://blog.ariacybersecurity.com/blog/tag/cyber-attack), [data breach](https://blog.ariacybersecurity.com/blog/tag/data-breach), [cybersecurity](https://blog.ariacybersecurity.com/blog/tag/cybersecurity), [data protection](https://blog.ariacybersecurity.com/blog/tag/data-protection)

<https://blog.ariacybersecurity.com/blog/how-azt-breaks-the-hugging-face-attack-chain>

## [HOW AZT BREAKS THE HUGGING FACE ATTACK CHAIN](https://blog.ariacybersecurity.com/blog/how-azt-breaks-the-hugging-face-attack-chain)

*( read )*

 Topics: [cyber attack](https://blog.ariacybersecurity.com/blog/tag/cyber-attack), [data breach](https://blog.ariacybersecurity.com/blog/tag/data-breach), [cybersecurity](https://blog.ariacybersecurity.com/blog/tag/cybersecurity), [data protection](https://blog.ariacybersecurity.com/blog/tag/data-protection)

<https://blog.ariacybersecurity.com/blog/cyberattacks-on-water-facilities-are-growing>

## [Cyberattacks on Water Facilities Are Growing- Here’s How This Critical Sector Can Fight Back](https://blog.ariacybersecurity.com/blog/cyberattacks-on-water-facilities-are-growing)

*( read )*

 Topics: [cyber attack](https://blog.ariacybersecurity.com/blog/tag/cyber-attack), [data breach](https://blog.ariacybersecurity.com/blog/tag/data-breach), [cybersecurity](https://blog.ariacybersecurity.com/blog/tag/cybersecurity), [data protection](https://blog.ariacybersecurity.com/blog/tag/data-protection)

- [Cybersecurity Products](https://www.ariacybersecurity.com/cybersecurity-products/) 
    - [All Cybersecurity Products](https://www.ariacybersecurity.com/cybersecurity-products/all-products/)
    - [ARIA SDS Applications](https://www.ariacybersecurity.com/cybersecurity-products/aria-sds-security-services/) 
          - [ARIA SDS AIR](https://www.ariacybersecurity.com/cybersecurity-products/aria-air/)
          - [ARIA Security Appliances](https://www.ariacybersecurity.com/cybersecurity-products/security-appliances/)
    - Solutions 
          - [Threat Detection and Response](https://www.ariacybersecurity.com/cybersecurity-products/threat-detection-response/)
          - [Data Protection](https://www.ariacybersecurity.com/cybersecurity-products/data-protection/)
          - [Industry Compliance](https://www.ariacybersecurity.com/cybersecurity-products/industry-compliance/)
          - [Protecting Commercial IoT](https://www.ariacybersecurity.com/cybersecurity-products/protecting-commercial-iot/)
- [Myricom SmartNICs](https://www.ariacybersecurity.com/network-adapters/) 
    - [Software](https://www.ariacybersecurity.com/network-adapters/software/) 
          - [Myricom DBL](https://www.ariacybersecurity.com/network-adapters/software/dbl/)
          - [MVA](https://www.ariacybersecurity.com/network-adapters/mva-software/)
          - [Myricom Sniffer 10G](https://www.ariacybersecurity.com/network-adapters/software/sniffer10g/)
    - Myricom ARC 
          - [C-Class](https://www.ariacybersecurity.com/network-adapters/c-class/)
          - [D-Class](https://www.ariacybersecurity.com/network-adapters/d-class/)
          - [E-Class](https://www.ariacybersecurity.com/network-adapters/e-class/)
    - [Myricom SIA SmartNIC](https://www.ariacybersecurity.com/network-adapters/myricom-sia/)
    - [Resellers & Distributors](https://www.ariacybersecurity.com/network-adapters/resellers-distributors/)
- MSSP and OEM Solutions 
    - [MSSP Solutions](https://www.ariacybersecurity.com/mssp-solutions/)
    - [OEM Solutions](https://www.ariacybersecurity.com/oem-solutions/)
- [About Us](https://www.ariacybersecurity.com/about-us/) 
    - [Careers](https://www.ariacybersecurity.com/about-us/careers/)
    - [Awards](https://www.ariacybersecurity.com/about-us/industry-awards-and-recognition/)
    - [News](https://www.ariacybersecurity.com/about-us/news/)
    - [Resources](https://www.ariacybersecurity.com/about-us/resources/)
- [Blog](https://blog.ariacybersecurity.com/blog)
- [Support](https://www.ariacybersecurity.com/support/)

- [Contact Us](https://www.ariacybersecurity.com/about-us/contact-us/)
- [Careers](https://www.ariacybersecurity.com/about-us/careers/)
- [Privacy Policy](https://www.ariacybersecurity.com/privacy-policy/)
- [Cybersecurity Terms and Conditions](https://www.ariacybersecurity.com/cybersecurity-terms-and-conditions/)
- [ADR and SAAS SOLUTIONS TERMS AND CONDITIONS](https://www.ariacybersecurity.com/aria-cybersecurity-terms-and-conditions-aria-adr-and-saas-solutions/)

- ## Social Links
  
  [![Support](https://www.ariacybersecurity.com/wp-content/uploads/2019/05/careers-icon.png)](https://blog.ariacybersecurity.com/about-us/careers) [![Support](https://www.ariacybersecurity.com/wp-content/uploads/2019/05/support-icon.png)](https://blog.ariacybersecurity.com/support) <https://twitter.com/ARIACyberSec> <https://www.linkedin.com/company/aria-cybersecurity-solutions> <https://www.facebook.com/ARIACyberSec/>
- ## Subscribe
  
  Enter your email address to subscribe to this blog and receive notifications of new posts by email.
- ## RSS Feed
  
  [RSS Feed](https://www.ariacybersecurity.com/blog/feed/)

© Copyright 2026 CSP Inc. All rights reserved.

ARIA Cybersecurity Solutions, are brought to market by the High Performance Products Division of CSP Inc. Myricom network products are manufactured, sold, and serviced by the HPP division of CSP Inc.

![ARIA GDPR Compliant](https://blog.ariacybersecurity.com/wp-content/uploads/2024/02/ARIA_GDPR_Compliant_IMG.png)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "ARIA Cybersecurity Solutions",
    "url" : "https://blog.ariacybersecurity.com/blog/author/aria-cybersecurity-solutions"
  },
  "dateModified" : "2024-02-29T12:38:38.395Z",
  "datePublished" : "2024-02-29T12:38:38.000Z",
  "headline" : "UnitedHealth Group’s Optum Subsidiary disrupted by Cyberattack | ARIA Cybersecurity",
  "image" : [ "https://blog.ariacybersecurity.com/hubfs/shutterstock_578912143.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.ariacybersecurity.com/blog/unitedhealth-groups-optum-subsidiary-disrupted-by-cyberattack",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.ariacybersecurity.com/hubfs/Aria_Logos_2025_RGB_Primary%20Horizontal.png"
    },
    "name" : "ARIA Cybersecurity Solutions"
  }
}
```