UnitedHealth Group, a major health-insurance company, was hit by a ransomware attack in 2024, causing significant disruptions.The attack targeted Change Healthcare, a platform acquired by UnitedHealth, impacting insurance claims processing.Recovery efforts took months, with some systems remaining partially available even a year later.The attackers bypassed two-factor authentication on the Citrix portal to initiate the attack.UnitedHealth Group paid a $22 million ransom to the BlackCat/ALPHV gang, leading to further complications.The cybercriminals claimed to have stolen extensive sensitive data, including medical records and financial documents.The financial losses for UnitedHealth from the breach were estimated at over $3 billion by the end of the year.Initial estimates of affected individuals at 100 million later rose to 190 million, revealing the massive impact of the breach.Lessons from the attack include the critical need for two-factor authentication and robust cybersecurity practices.Companies are advised to implement multilayered defenses, raise employee awareness, and engage external threat-hunting services.