$870 Million. That was the staggering cost of the cyberattack against United Healthcare’s Change Healthcare subsidiary in the first quarter of 2024.
According to CEO Andrew Witty, the data breach was caused by insufficient use of MFA, or multifactor authentication. Hackers stole a password unprotected with MFA—an additional verification step such as entering a code sent to a phone or authentication app—and used it to breach Change Healthcare’s computer network. They installed ransomware that disrupted payment and claims processing.
United Healthcare was not alone. Findings from the Identity Theft Resource Center (ITRC) indicate a 1,170% increase in data breach victims from the second quarter of 2023 to the same period this year. More than 1 billion corporations and individuals became data breach victims in the first half of 2024, a 490% increase over the first half of 2023.
Yes& is joining with its cybersecurity clients in recognizing October as Cybersecurity Awareness Month, because awareness is the single best tool in keeping people and organizations safe from online threats. Like the breach at United Healthcare, the great majority of cyberattacks could be prevented with four simple steps identified by the Cybersecurity and Infrastructure Security Agency (CISA).
These four steps have two things in common: They’re highly effective; and they require a change in behavior that few individuals or employees are likely to make without a strong nudge.
Yes& has worked with many clients to help motivate safe behaviors. If you want to gain the benefit of greater cybersecurity in your company, organization, or agency, celebrate Cybersecurity Awareness Month by consulting with Yes& about a cybersecurity campaign or initiative.