In April 2024, UnitedHealth Group's chief executive confirmed what had been visible on the blockchain for weeks: the company had paid a ransom — around $22 million in bitcoin — following the catastrophic February attack on its Change Healthcare subsidiary. The stated reasoning was the one every board eventually reaches for: it was, in his words, one of the hardest decisions he had made, taken to protect patient data.
What happened next belongs in every negotiation playbook. The ALPHV/BlackCat operation, which ran the attack as a service, received the payment — and then vanished, posting a fake law-enforcement seizure notice on its own leak site and disappearing with the money. The affiliate who had actually carried out the intrusion, and who was owed a cut, got nothing. Still holding the stolen data, that affiliate simply took it to a different extortion brand and demanded payment from UnitedHealth all over again. The $22 million had purchased precisely nothing: not deletion, not silence, not even one criminal's satisfaction.
The eventual scale confirmed the futility. The Change Healthcare breach was ultimately reported to have affected around 190 million people — the largest healthcare data breach in US history — and the data was never meaningfully contained. April 2024 is the case study cited whenever someone argues that a ransom payment buys certainty. It buys a receipt from a criminal, and the criminal's business model does not include honouring it. Britain's proposal, nine months later, to ban public-sector ransom payments outright drew directly on months like this one.
MITRE breached through the edge
In mid-April, MITRE — the organisation that maintains the CVE list and the ATT&CK framework the entire industry uses to describe attacks — disclosed that a nation-state actor had breached one of its own research networks, entering through the same Ivanti Connect Secure zero-days that had been under mass exploitation since January. There is no schadenfreude in it; MITRE had followed the vendor's guidance. The lesson was the harder one: when an edge appliance is being exploited at scale, following the published advice may not be sufficient, and even the organisation that writes the taxonomy of attacks is inside it.
ArcaneDoor and the firewall problem
Late in April, Cisco disclosed ArcaneDoor — a state-sponsored campaign that had been compromising its security appliances at government targets using two zero-days, with implants that survived reboots. Combined with the Ivanti crisis, it made 2024's edge-device pattern impossible to miss: the appliances organisations buy specifically to secure their perimeter had become the perimeter's weakest point, running opaque firmware, rarely monitored, and sitting by design at the exact boundary an attacker wants. It is the same theme that would return with F5 in October 2025.
A digital election, watched closely
India spent April in the opening phase of the largest election in human history, and its security establishment spent the month braced for two things that had dominated pre-election commentary: disruption of digital infrastructure, and AI-generated disinformation at scale. The technical attacks largely did not materialise; the synthetic media did, in volume — cloned voices of political figures, fabricated endorsements, and cheaply localised video circulating on messaging platforms faster than fact-checkers could respond. It was an early, instructive demonstration that the cyber threat to an election is not always an attack on a system. Sometimes it is an attack on the electorate, and the defending institution is journalism rather than a SOC.
⏳ Time capsule — April 2024
- A total solar eclipse crossed North America on April 8, briefly uniting a continent in looking upward rather than at screens.
- Bitcoin's fourth halving arrived on April 19 — an event ransomware economists watched as closely as traders did.
- "Should we pay?" became a boardroom question with a newly citable answer.
- Edge-appliance patch advisories arrived at a pace that exhausted the teams meant to apply them.
Paying is not a strategy
The $22 million that bought nothing became the reference case in the ransom-payment debate, cited in the UK Home Office's January 2025 consultation on banning payments and in insurers' repricing of extortion cover. Change Healthcare's final tally of roughly 190 million people affected still stands as the largest healthcare breach on record, and its two-month payments outage reshaped how US regulators think about concentration in medical claims processing. The edge-device pattern that let attackers into MITRE only intensified — Ivanti in 2024, Fortinet through 2025, F5 in October 2025 — until "assume your security appliance is a target, not a shield" became simply how mature teams operate.