On February 21, 2024, Change Healthcare — a UnitedHealth subsidiary that processes a very large share of America's medical claims — was hit by ALPHV/BlackCat ransomware and pulled its systems offline. What followed was not primarily a data-breach story, though it became the largest of those too. It was a liquidity crisis. Pharmacies could not verify coverage or process prescriptions. Providers could not submit claims and therefore could not be paid. Practices that operate on thin margins and fortnightly cash cycles went, within weeks, from healthy to distressed — some taking emergency loans, some cutting staff, a few closing.
The outage ran for months rather than days. Federal agencies improvised advance payments and regulatory flexibilities to keep providers solvent. Investigators later established a mundane entry point: remote-access infrastructure reachable without multi-factor authentication — the same failure pattern that would define the Snowflake campaign three months later. And the data theft, once counted, reached roughly 190 million individuals: the largest healthcare breach in US history, exposing not just identity data but diagnoses, treatments, and claims.
February 2024 belongs in this archive as the month systemic concentration became undeniable. Change Healthcare was not a household name, was not chosen by any patient, and had accumulated its position through decades of consolidation in medical billing. When it stopped, a substantial share of an entire national healthcare economy stopped with it — and the only reason more people did not notice sooner is that the failure was in the plumbing rather than the ward.
Operation Cronos seizes LockBit
On February 19–20, an international law-enforcement coalition led by the UK's National Crime Agency seized LockBit's infrastructure — and then did something unusual with it. Rather than simply posting a seizure notice, investigators kept the gang's own leak site running and used it to publish their findings: how many affiliates there were, how the operation worked, and the pointed detail that LockBit had not always deleted victims' data after ransoms were paid. Arrests, sanctions, indictments, and decryption keys followed. LockBit limped on, but the psychological blow was the point: the takedown attacked the gang's credibility with its own criminal customers, and it never fully recovered — a decline this archive follows to its humiliating hack in May 2025.
Ivanti's very long January
February brought no relief from the Ivanti Connect Secure emergency that had opened the year. Fresh vulnerabilities kept arriving, mitigations proved incomplete, and organisations that had followed each successive instruction discovered they were still exposed. US federal agencies had already been ordered to disconnect the appliances entirely. For defenders, the lasting lesson was about trust in remediation: when a product line is under sustained attack, "we applied the vendor's fix" is a statement about effort, not about safety.
boAt, and 7.5 million young customers
In February 2024, boAt — one of India's most recognisable consumer-electronics brands, built on earbuds and smartwatches sold largely to young, phone-first buyers — suffered a breach exposing the personal data of more than 7.5 million customers, with roughly two gigabytes of names, addresses, phone numbers, email addresses, and customer IDs surfacing on dark-web forums. There was no ransomware drama and little national outcry; the data simply appeared, cheap and downloadable. It was, in its ordinariness, the more representative Indian breach of 2024: a fast-growing consumer brand that had scaled its customer base far faster than its security function, and a customer base with no practical recourse. A year later, that gap was precisely what the DPDP Rules were written to close.
Sora arrives, and Gemini stumbles
OpenAI unveiled Sora on 15 February 2024: a text-to-video model that produced up to a minute of high-definition footage from a written prompt. It was not a product. Access went to red-teamers assessing risk and to a small group of visual artists, designers and filmmakers; the public waited until December that year, when Sora arrived as a paid feature for ChatGPT subscribers. Google had a crowded month either side of it. On 8 February it retired the Bard name, folded the assistant into Gemini and launched a paid Gemini Advanced tier; on 15 February, the same day as Sora and largely eclipsed by it, it announced Gemini 1.5 Pro, shipping with a 128,000-token context window and an experimental one-million-token window open only to a limited private preview. Then on 22 February it paused Gemini's generation of images of people after historically inaccurate depictions drew criticism, conceding the model had got it wrong; the feature returned in late August. From 2026, February reads as the month generated video stopped being a demo and the month guardrails became a public argument.
Free decryptors, and a fine for Avast
February's takedown left a practical question behind it: what becomes of the victims already encrypted. The answer came from law enforcement rather than the vendors. Working from LockBit's seized infrastructure, the National Crime Agency, the FBI and Japan's police, supported by Europol, built decryption tools and published them free on No More Ransom, the public-private decryptor portal; the NCA said it held more than a thousand keys and would approach UK victims. Vendors shaped the operation elsewhere: Trend Micro's dissection of LockBit-NG-Dev, an unfinished successor encryptor rewritten in .NET, was done with the NCA. The same week brought scrutiny of the industry itself. On 22 February the US Federal Trade Commission announced an order, finalised that June, requiring Avast to pay $16.5 million and barring it from selling browsing data for advertising, alleging that a firm selling tracking protection had routed users' browsing histories to its Jumpshot subsidiary. Avast, which had closed Jumpshot in January 2020, said it disagreed with the allegations but was pleased to resolve the matter; the FTC did not open its refund process until February 2025.
⏳ Time capsule — February 2024
- Apple's Vision Pro went on sale on February 2, and the technology press spent a fortnight wearing it in public.
- US pharmacies posted handwritten signs explaining they could not process insurance — the outage's most visible artefact.
- Law enforcement's LockBit trolling was widely praised as the most effective piece of counter-ransomware communication yet attempted.
- Bitcoin climbed back above $50,000 for the first time in more than two years.
Concentration, named at last
Change Healthcare became the permanent reference for systemic third-party risk in critical services, driving US regulatory attention to healthcare-sector concentration and cyber requirements — and its April sequel, the $22 million ransom that bought nothing, made it a lesson in negotiation as well. Its 190-million-person tally still stands as the largest healthcare breach on record. Operation Cronos, meanwhile, proved that disrupting a ransomware brand's reputation can outperform disrupting its servers, a template law enforcement has reused since. And boAt's quiet leak is the kind of incident this archive keeps recording from India: not the loudest breach of the month, but the most typical — and the reason a rulebook eventually arrived.