Was just debating this today.
Mandiant was confirmed as the outside IR retainer for the investigation, so if they were the ones who slapped the nation-state attribution label on I’d more so believe it and then lean away from the ransomware-as-a-service theory. Mandiant usually know better than to toss the state-sponsored label around or mark financially motivated groups like ALPHV as such.
But if that was UHC’s own verbiage, not a good look. May have picked it to better rationalize the additional outages done for mitigation purposes. Especially since it was in an Edgar report. Investors be big mad otherwise.