On February 21, 2024, Change Healthcare — a UnitedHealth subsidiary that processes a very large share of America's medical claims — was hit by ALPHV/BlackCat ransomware and pulled its systems offline. What followed was not primarily a data-breach story, though it became the largest of those too. It was a liquidity crisis. Pharmacies could not verify coverage or process prescriptions. Providers could not submit claims and therefore could not be paid. Practices that operate on thin margins and fortnightly cash cycles went, within weeks, from healthy to distressed — some taking emergency loans, some cutting staff, a few closing.

The outage ran for months rather than days. Federal agencies improvised advance payments and regulatory flexibilities to keep providers solvent. Investigators later established a mundane entry point: remote-access infrastructure reachable without multi-factor authentication — the same failure pattern that would define the Snowflake campaign three months later. And the data theft, once counted, reached roughly 190 million individuals: the largest healthcare breach in US history, exposing not just identity data but diagnoses, treatments, and claims.

February 2024 belongs in this archive as the month systemic concentration became undeniable. Change Healthcare was not a household name, was not chosen by any patient, and had accumulated its position through decades of consolidation in medical billing. When it stopped, a substantial share of an entire national healthcare economy stopped with it — and the only reason more people did not notice sooner is that the failure was in the plumbing rather than the ward.

Also that month · The takedown that trolled

Operation Cronos seizes LockBit

On February 19–20, an international law-enforcement coalition led by the UK's National Crime Agency seized LockBit's infrastructure — and then did something unusual with it. Rather than simply posting a seizure notice, investigators kept the gang's own leak site running and used it to publish their findings: how many affiliates there were, how the operation worked, and the pointed detail that LockBit had not always deleted victims' data after ransoms were paid. Arrests, sanctions, indictments, and decryption keys followed. LockBit limped on, but the psychological blow was the point: the takedown attacked the gang's credibility with its own criminal customers, and it never fully recovered — a decline this archive follows to its humiliating hack in May 2025.

Also that month · The edge crisis deepens

Ivanti's very long January

February brought no relief from the Ivanti Connect Secure emergency that had opened the year. Fresh vulnerabilities kept arriving, mitigations proved incomplete, and organisations that had followed each successive instruction discovered they were still exposed. US federal agencies had already been ordered to disconnect the appliances entirely. For defenders, the lasting lesson was about trust in remediation: when a product line is under sustained attack, "we applied the vendor's fix" is a statement about effort, not about safety.

India desk · February 2024

boAt, and 7.5 million young customers

In February 2024, boAt — one of India's most recognisable consumer-electronics brands, built on earbuds and smartwatches sold largely to young, phone-first buyers — suffered a breach exposing the personal data of more than 7.5 million customers, with roughly two gigabytes of names, addresses, phone numbers, email addresses, and customer IDs surfacing on dark-web forums. There was no ransomware drama and little national outcry; the data simply appeared, cheap and downloadable. It was, in its ordinariness, the more representative Indian breach of 2024: a fast-growing consumer brand that had scaled its customer base far faster than its security function, and a customer base with no practical recourse. A year later, that gap was precisely what the DPDP Rules were written to close.

⏳ Time capsule — February 2024

  • Apple's Vision Pro went on sale on February 2, and the technology press spent a fortnight wearing it in public.
  • US pharmacies posted handwritten signs explaining they could not process insurance — the outage's most visible artefact.
  • Law enforcement's LockBit trolling was widely praised as the most effective piece of counter-ransomware communication yet attempted.
  • Bitcoin climbed back above $50,000 for the first time in more than two years.
Where it stands today — 2026

Concentration, named at last

Change Healthcare became the permanent reference for systemic third-party risk in critical services, driving US regulatory attention to healthcare-sector concentration and cyber requirements — and its April sequel, the $22 million ransom that bought nothing, made it a lesson in negotiation as well. Its 190-million-person tally still stands as the largest healthcare breach on record. Operation Cronos, meanwhile, proved that disrupting a ransomware brand's reputation can outperform disrupting its servers, a template law enforcement has reused since. And boAt's quiet leak is the kind of incident this archive keeps recording from India: not the loudest breach of the month, but the most typical — and the reason a rulebook eventually arrived.