What happened
Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.
How the deception worked
The attacker impersonated one of Magellan's own clients, which is a stronger pretext than a generic executive spoof because a managed care company's staff correspond with client organisations constantly and are expected to be responsive to them. The employee provided access credentials in response to that message. Over the following five days the attackers moved through the network, reached a corporate server holding employee records including tax documentation with Social Security numbers, exfiltrated a subset of it, and installed software to harvest further log-ins before triggering encryption. The five-day dwell time is where the data theft happened.
The control that would have caught it· our reading, not a claim from the sources
Client-impersonation phishing defeats seniority-based suspicion, so the control is MFA plus detection of internal reconnaissance in the days between the click and the encryption.
Sources (2)
- Data Stolen in Magellan Health Ransomware AttackHIPAA Journal·hipaajournal.comOpen ↗
- Healthcare giant Magellan Health hit by ransomware attackBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.