HHS website

Cyber Attack Hits Department of Health and Human Services Amid Government Coronavirus Response

HHS officials said no personal data was accessed and the attack was not successful. But it could be a sign of things to come during the coronavirus pandemic.

A cyber attack hit the Department of Health and Human Services on Sunday night that aimed to undermine the efforts of the agency to respond to the COVID-19 pandemic, according to Bloomberg News.

A foreign state is suspected in the attack, but the Trump administration has not confirmed what country was behind the effort. John Ullyot, a spokesman for the National Security Council, told Bloomberg that HHS and federal networks were “functioning normally” by Monday.

“We are aware of a cyber incident related to the Health and Human Services computer networks, and the federal government is investigating this incident thoroughly,” Ullyot said in a statement. “HHS and federal government cybersecurity professionals are continuously monitoring and taking appropriate actions to secure our federal networks.”

While Bloomberg originally referred to the cyber attack as a “hack,” later reports found that the incident actually involved a DDos (distributed denial of service) attack that does not involve a full breach. The agency’s servers were hit with millions of pageviews that are meant to slow the site down or bring it offline entirely, according to Recode.

The attack was ultimately not successful and no data was accessed, according to Bloomberg and follow-up reports. Caitlin B. Oakley, a spokesperson for HHS, also told Recode that the department’s cyber infrastructure was solid and “fully operational.”

“Early on while preparing and responding to Covid-19, HHS put extra protections in place,” Oakley said. “HHS has an IT infrastructure with risk-based security controls continuously monitored in order to detect and address cybersecurity threats and vulnerabilities.”

Washington Post national security reporter Ellen Nakashima later shared comments from a source at the Department of Homeland Security, who said that reports of the HHS attack were “overblown.” On a scale of 1 to 10, the incident registered as a 2, the source said.

On Tuesday, ZDNET reporter Catalin Cimpanu questioned if the “cyber incident” would even classify as an attack, as his DDoS mitigation services sources said they did not see an attack aimed at the HHS site. The issue looked like a “spike of legitimate traffic aimed at a website of interest to the general public,” Cimpanu wrote.

However serious the incident might have been, it could be a sign of events to come in the country’s efforts to combat the coronavirus pandemic.

In the past few months, security researchers have identified a surge of phishing campaigns trying to convince people to visit malicious coronavirus-related sites, preying on fear to get their personal information. In addition, State Department officials have previously linked disinformation campaigns about the virus to a Russian operation behind “swarms of online, false personas” spreading conspiracy theories online

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3