HHS website

Cyber Attack Hits Department of Health and Human Services Amid Government Coronavirus Response

HHS officials said no personal data was accessed and the attack was not successful. But it could be a sign of things to come during the coronavirus pandemic.

A cyber attack hit the Department of Health and Human Services on Sunday night that aimed to undermine the efforts of the agency to respond to the COVID-19 pandemic, according to Bloomberg News.

A foreign state is suspected in the attack, but the Trump administration has not confirmed what country was behind the effort. John Ullyot, a spokesman for the National Security Council, told Bloomberg that HHS and federal networks were “functioning normally” by Monday.

“We are aware of a cyber incident related to the Health and Human Services computer networks, and the federal government is investigating this incident thoroughly,” Ullyot said in a statement. “HHS and federal government cybersecurity professionals are continuously monitoring and taking appropriate actions to secure our federal networks.”

While Bloomberg originally referred to the cyber attack as a “hack,” later reports found that the incident actually involved a DDos (distributed denial of service) attack that does not involve a full breach. The agency’s servers were hit with millions of pageviews that are meant to slow the site down or bring it offline entirely, according to Recode.

The attack was ultimately not successful and no data was accessed, according to Bloomberg and follow-up reports. Caitlin B. Oakley, a spokesperson for HHS, also told Recode that the department’s cyber infrastructure was solid and “fully operational.”

“Early on while preparing and responding to Covid-19, HHS put extra protections in place,” Oakley said. “HHS has an IT infrastructure with risk-based security controls continuously monitored in order to detect and address cybersecurity threats and vulnerabilities.”

Washington Post national security reporter Ellen Nakashima later shared comments from a source at the Department of Homeland Security, who said that reports of the HHS attack were “overblown.” On a scale of 1 to 10, the incident registered as a 2, the source said.

On Tuesday, ZDNET reporter Catalin Cimpanu questioned if the “cyber incident” would even classify as an attack, as his DDoS mitigation services sources said they did not see an attack aimed at the HHS site. The issue looked like a “spike of legitimate traffic aimed at a website of interest to the general public,” Cimpanu wrote.

However serious the incident might have been, it could be a sign of events to come in the country’s efforts to combat the coronavirus pandemic.

In the past few months, security researchers have identified a surge of phishing campaigns trying to convince people to visit malicious coronavirus-related sites, preying on fear to get their personal information. In addition, State Department officials have previously linked disinformation campaigns about the virus to a Russian operation behind “swarms of online, false personas” spreading conspiracy theories online

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West
  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.