By NHI Mgmt Group Editorial TeamBased on Oasis Security: “The Future of Identity Security: Lessons from the Change Health Breach” (May 1, 2026)

TL;DR: Change Healthcare was breached through compromised credentials to a Citrix remote access portal without MFA, followed by lateral movement, data exfiltration, and a $22 million ransom payment, according to Oasis Security and UnitedHealth Group. The incident shows why MFA is necessary for human access but insufficient when identity governance does not extend to non-human identities and remote access pathways.


At a glance

What this is: This is an analysis of the Change Healthcare breach and the finding that MFA alone did not prevent compromise after credentials were used against a Citrix portal.

Why it matters: It matters because IAM teams need to separate human authentication controls from NHI governance, remote access hardening, and the downstream blast radius of compromised credentials.

By the numbers:

  • Non-human identities can outnumber human identities by 10x-50x in modern environments, according to Oasis Security.

Context

The core security gap here is not simply missing MFA, but the assumption that protecting a login path also protects the wider identity fabric. When compromised credentials can reach a remote access portal, the control boundary becomes the access pathway, not the password prompt.

Non-human identities such as service accounts, APIs and tokens sit outside human MFA workflows, yet they often hold the access needed for lateral movement and data access. That means identity programmes that stop at human authentication can leave a large part of the operational attack surface unmanaged.

Change Healthcare is a typical example of a modern identity breach pattern rather than an outlier: a human-facing control failed first, then the attacker exploited the surrounding identity and access environment for broader impact.


Key questions

Q: What breaks when a remote access portal does not require MFA?

A: Password-only remote access turns stolen credentials into immediate session access, which means the attacker can enter through a normal user path and blend into routine activity. In a high-value environment, that single failure can become lateral movement, data theft, and ransomware if detection and containment are not already tuned to identity behaviour.

Q: Why do compromised credentials often bypass MFA controls?

A: Because many attacks steal the artifact issued after MFA, not the password itself. If an attacker reuses a session cookie, OAuth token, or refresh token, the login appears already authenticated. MFA was satisfied earlier, so the control did its job but did not protect the downstream artifact from replay.

Q: How do security teams know whether remote admin access is too broad?

A: Look for accounts that can reach servers, stop services, or manage recovery tooling without task-specific approval or expiry. If the same identity can authenticate broadly and make destructive changes, the access model is overextended. Audit RDP entitlements, backup rights, and service-control permissions together, not separately.

Q: How should teams govern non-human identities that support remote access and back-end workflows?

A: They should govern them as distinct identities with explicit ownership, scoped permissions, rotation, revocation and offboarding. Service accounts, tokens and API keys cannot rely on human MFA, so their lifecycle controls must be designed around reach and persistence. The goal is to prevent machine access from becoming the hidden path through the environment.


Technical breakdown

Why MFA on the portal did not stop the breach

Multi-factor authentication protects the authentication step, but it does not remediate compromised credentials that already satisfy the first factor or stop misuse once a session is established. In this case, the Citrix portal was used as the entry point for remote access to desktops, which meant the attacker only needed valid access to begin exploring connected systems. MFA reduces the chance of straightforward login abuse, but it is not a substitute for device trust, session risk controls, or identity lifecycle governance around the accounts and secrets that can reach that portal.

Practical implication: treat MFA as one control layer, not the end of identity risk management for remote access.

How lateral movement changes the control problem

Lateral movement is the phase where an attacker turns one valid foothold into broader internal access. Once inside, threat actors often move from the initial remote access point to higher-value systems by reusing trust relationships, weak segmentation, or over-permissive accounts. In a breach like this, the real security failure is not just that the door opened, but that the interior identity model allowed movement without enough friction, containment or privilege boundaries. That is where identity governance, network segmentation and privilege constraints intersect.

Practical implication: review where remote access identities can pivot into internal systems without additional authorisation or containment.

Why the NHI fabric matters when human MFA is present

Non-human identities are service accounts, API keys, tokens and certificates that run business processes without a person present. They are not protected by human MFA, and they often have durable access that persists beyond the life of a specific user session. When an environment has many more NHIs than humans, the security programme must govern issuance, ownership, rotation and offboarding as a first-class control plane. Otherwise, an attacker can exploit the surrounding identity mesh even if the front door has MFA.

Practical implication: map which non-human identities can reach the same systems as remote users and govern them as separately as possible.


Threat narrative

Attacker objective: The attacker’s objective was to gain internal access, exfiltrate data and then amplify pressure through ransomware.

  1. Entry occurred when criminals used compromised credentials to access a Change Healthcare Citrix remote access portal that did not require MFA.
  2. Escalation followed as the threat actor moved laterally within connected systems and reached more sensitive areas of the environment.
  3. Impact came later when ransomware was deployed nine days after initial access, after data had already been exfiltrated.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.
  • Change Healthcare breach 2024: A stolen login on a Citrix portal without MFA led to ALPHV ransomware, a $22 million ransom and 192.7 million people affected.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

MFA-only thinking breaks at the boundary between authentication and governance: This breach worked because the security programme treated MFA as a sufficient endpoint rather than one layer in a larger identity model. Compromised credentials still opened a path into a remote access portal, and the surrounding access fabric allowed the attacker to keep going. The implication is that authentication strength and identity governance must be evaluated separately, not collapsed into one control story.

Remote access portals become identity concentration points when they connect into flat internal trust structures: Once a valid session exists, the attacker is inside the trust zone, not outside it. If segmentation, privilege boundaries and session controls are weak, a single access path can produce disproportionate blast radius. Practitioners should read this as a warning about architectural trust, not just login hygiene.

Non-human identities are the missing control plane in many breach analyses: The article correctly notes that NHIs outnumber humans by large multiples and cannot rely on MFA. That makes ownership, rotation, offboarding and scope control central to risk reduction. When the identity fabric includes service accounts, APIs and tokens, security teams need separate governance for machine access rather than extending human controls by analogy.

Ephemeral access assumptions failed to match the persistence of attacker opportunity: Access review processes assume the relevant identity state lasts long enough to be reviewed. In this breach pattern, once compromised credentials and remote access were available, the attacker had enough time to move laterally and deploy ransomware after the initial foothold. The lesson is that governance cadence must be judged against attacker dwell time, not administrative convenience.

Identity blast radius is now the more useful lens than isolated authentication success: A control can work at the login layer and still fail at the programme layer if downstream systems are reachable with the same trust. That is why practitioners should measure how far a compromised identity can travel, what it can touch, and how quickly it can be contained. The practical conclusion is to govern reach, not just entry.

From our research library:

What this signals

Identity blast radius is the more useful operational measure here: The relevant question is not whether MFA exists, but how far a compromised identity can move before controls intervene. When a remote access session can pivot into internal systems, the programme has a containment problem, not just an authentication problem.

Machine and human access need separate governance paths: Service accounts, API keys and tokens do not benefit from human MFA, so the control model has to change at issuance, rotation and offboarding. That separation is where identity governance becomes operational rather than symbolic.

Compromised credentials remain a dominant breach path, according to the Ultimate Guide to NHIs: 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs. For programmes that still centre human login security, the signal is clear: governance has to follow the credential, not just the user.


For practitioners

  • Harden remote access pathways Review every portal that allows remote entry into internal systems and require step-up controls where privileged or sensitive access is reachable after authentication.
  • Inventory non-human identities by reach Map service accounts, API keys, tokens and certificates that can reach the same systems as user logins, then separate them by ownership and business purpose.
  • Reduce lateral movement paths Limit what a successfully authenticated remote session can reach by tightening segmentation, privilege scope and session-based access boundaries.
  • Shorten credential exposure windows Rotate and retire credentials that can access remote administration or desktop infrastructure, especially where usage is no longer clearly tied to a current owner.
  • Test identity blast radius Simulate what a compromised remote access account can touch in your environment, then remove unnecessary trust relationships and over-permissive access.

Key takeaways

  • The breach shows how MFA can fail to contain risk when compromised credentials can still reach a remote access portal and pivot inward.
  • The broader lesson is that identity governance must cover both human authentication and the non-human access fabric that supports internal systems.
  • Teams should measure identity blast radius, not just login protection, because the decisive failure is often how far access can travel after entry.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe breach began with compromised credentials and weak portal authentication.
NHI-05 — Overprivileged NHILateral movement risk grows when authenticated identities can reach too much.
NHI-07 — Long-Lived SecretsCompromised credentials and durable access windows are central to this attack pattern.
Recommendation — Apply NHI-04 to enforce stronger authentication paths for remote access and machine-adjacent identities. Use NHI-05 to reduce the reach of accounts, tokens and service access that can pivot into internal systems. Use NHI-07 to shorten credential exposure windows and retire stale secrets tied to remote access.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAuthenticator lifecycle control is relevant to the compromised credential path.
Recommendation — Apply IA-5 to manage credential issuance, rotation and revocation for access paths like Citrix portals.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe attack used stolen credentials and then moved laterally inside the environment.
Recommendation — Map the breach to TA0006 and TA0008 to improve detection and containment of credential-driven internal movement.

Key terms

  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
  • Lateral Movement: A post-compromise technique where an attacker uses a compromised NHI to move through a network, accessing additional systems and escalating impact without triggering detection.
  • Authenticator Lifecycle Management: Authenticator lifecycle management is the governance of a credential from issuance to renewal, replacement, and retirement. For human identity programmes, it ensures that keys, smart cards, and certificates stay tied to the right user and are removed when the user, role, or device is no longer trusted.

Deepen your knowledge

NHI governance, machine identity security, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org