In April 2024, UnitedHealth Group's chief executive confirmed what had been visible on the blockchain for weeks: the company had paid a ransom — around $22 million in bitcoin — following the catastrophic February attack on its Change Healthcare subsidiary. The stated reasoning was the one every board eventually reaches for: it was, in his words, one of the hardest decisions he had made, taken to protect patient data.

What happened next belongs in every negotiation playbook. The ALPHV/BlackCat operation, which ran the attack as a service, received the payment — and then vanished, posting a fake law-enforcement seizure notice on its own leak site and disappearing with the money. The affiliate who had actually carried out the intrusion, and who was owed a cut, got nothing. Still holding the stolen data, that affiliate simply took it to a different extortion brand and demanded payment from UnitedHealth all over again. The $22 million had purchased precisely nothing: not deletion, not silence, not even one criminal's satisfaction.

The eventual scale confirmed the futility. The Change Healthcare breach was ultimately reported to have affected around 190 million people — the largest healthcare data breach in US history — and the data was never meaningfully contained. April 2024 is the case study cited whenever someone argues that a ransom payment buys certainty. It buys a receipt from a criminal, and the criminal's business model does not include honouring it. Britain's proposal, nine months later, to ban public-sector ransom payments outright drew directly on months like this one.

Also that month · The cataloguer catalogued

MITRE breached through the edge

In mid-April, MITRE — the organisation that maintains the CVE list and the ATT&CK framework the entire industry uses to describe attacks — disclosed that a nation-state actor had breached one of its own research networks, entering through the same Ivanti Connect Secure zero-days that had been under mass exploitation since January. There is no schadenfreude in it; MITRE had followed the vendor's guidance. The lesson was the harder one: when an edge appliance is being exploited at scale, following the published advice may not be sufficient, and even the organisation that writes the taxonomy of attacks is inside it.

Also that month · Hunting the perimeter

ArcaneDoor and the firewall problem

Late in April, Cisco disclosed ArcaneDoor — a state-sponsored campaign that had been compromising its security appliances at government targets using two zero-days, with implants that survived reboots. Combined with the Ivanti crisis, it made 2024's edge-device pattern impossible to miss: the appliances organisations buy specifically to secure their perimeter had become the perimeter's weakest point, running opaque firmware, rarely monitored, and sitting by design at the exact boundary an attacker wants. It is the same theme that would return with F5 in October 2025.

India desk · April 2024

A digital election, watched closely

India spent April in the opening phase of the largest election in human history, and its security establishment spent the month braced for two things that had dominated pre-election commentary: disruption of digital infrastructure, and AI-generated disinformation at scale. The technical attacks largely did not materialise; the synthetic media did, in volume — cloned voices of political figures, fabricated endorsements, and cheaply localised video circulating on messaging platforms faster than fact-checkers could respond. It was an early, instructive demonstration that the cyber threat to an election is not always an attack on a system. Sometimes it is an attack on the electorate, and the defending institution is journalism rather than a SOC.

AI Tech desk · April 2024

Llama 3 and the small-model turn

Meta released Llama 3 on 18 April 2024, in 8-billion and 70-billion parameter versions trained on some fifteen trillion tokens, and put the same model behind its Meta AI assistant; a far larger model, above 400 billion parameters, was still training and arrived as Llama 3.1 the following July. The licence carried the argument that has trailed the family since: weights anyone could download, under terms Meta called open and the Open Source Initiative has repeatedly declined to accept as open source. The rest of the month ran smaller. Microsoft announced Phi-3 on 23 April, a 3.8-billion-parameter model sized for a handset; Apple published its OpenELM family on Hugging Face the next day, from 270 million to three billion parameters and explicitly built to run on the device rather than in a data centre; Snowflake released Arctic the same day. Apple's intent became legible in June, when Apple Intelligence was announced at WWDC, and by 2026 the small on-device model is an assumed layer of the stack rather than a curiosity.

Digital Guard desk · April 2024

Copilot ships, Darktrace changes hands

On 1 April 2024 Microsoft made Copilot for Security generally available, moving a generative-AI assistant for security teams off the preview list and onto a price list. It was sold by consumption rather than by seat, billed through a new Security Compute Unit at four dollars an hour with three units the recommended starting provision — which obliged buyers to price an assistant by the hour before anyone had established what an hour of it was worth. It was later renamed Microsoft Security Copilot. The month closed on the other side of the same trade: on 26 April Thoma Bravo announced a recommended cash offer for Darktrace at around $5.3 billion, roughly a fifth above the previous close, for a British firm whose entire proposition was AI-based detection — and whose accounts a short seller had attacked in 2023, allegations the company denied and an Ernst & Young review found no cause to restate. The deal completed that October. Two years on, an assistant in the console is unremarkable; the argument is about what it costs to run.

⏳ Time capsule — April 2024

  • A total solar eclipse crossed North America on April 8, briefly uniting a continent in looking upward rather than at screens.
  • Bitcoin's fourth halving arrived on April 19 — an event ransomware economists watched as closely as traders did.
  • "Should we pay?" became a boardroom question with a newly citable answer.
  • Edge-appliance patch advisories arrived at a pace that exhausted the teams meant to apply them.
Where it stands today — 2026

Paying is not a strategy

The $22 million that bought nothing became the reference case in the ransom-payment debate, cited in the UK Home Office's January 2025 consultation on banning payments and in insurers' repricing of extortion cover. Change Healthcare's final tally of roughly 190 million people affected still stands as the largest healthcare breach on record, and its two-month payments outage reshaped how US regulators think about concentration in medical claims processing. The edge-device pattern that let attackers into MITRE only intensified — Ivanti in 2024, Fortinet through 2025, F5 in October 2025 — until "assume your security appliance is a target, not a shield" became simply how mature teams operate.