HHS website

Cyber Attack Hits Department of Health and Human Services Amid Government Coronavirus Response

HHS officials said no personal data was accessed and the attack was not successful. But it could be a sign of things to come during the coronavirus pandemic.

A cyber attack hit the Department of Health and Human Services on Sunday night that aimed to undermine the efforts of the agency to respond to the COVID-19 pandemic, according to Bloomberg News.

A foreign state is suspected in the attack, but the Trump administration has not confirmed what country was behind the effort. John Ullyot, a spokesman for the National Security Council, told Bloomberg that HHS and federal networks were “functioning normally” by Monday.

“We are aware of a cyber incident related to the Health and Human Services computer networks, and the federal government is investigating this incident thoroughly,” Ullyot said in a statement. “HHS and federal government cybersecurity professionals are continuously monitoring and taking appropriate actions to secure our federal networks.”

While Bloomberg originally referred to the cyber attack as a “hack,” later reports found that the incident actually involved a DDos (distributed denial of service) attack that does not involve a full breach. The agency’s servers were hit with millions of pageviews that are meant to slow the site down or bring it offline entirely, according to Recode.

The attack was ultimately not successful and no data was accessed, according to Bloomberg and follow-up reports. Caitlin B. Oakley, a spokesperson for HHS, also told Recode that the department’s cyber infrastructure was solid and “fully operational.”

“Early on while preparing and responding to Covid-19, HHS put extra protections in place,” Oakley said. “HHS has an IT infrastructure with risk-based security controls continuously monitored in order to detect and address cybersecurity threats and vulnerabilities.”

Washington Post national security reporter Ellen Nakashima later shared comments from a source at the Department of Homeland Security, who said that reports of the HHS attack were “overblown.” On a scale of 1 to 10, the incident registered as a 2, the source said.

On Tuesday, ZDNET reporter Catalin Cimpanu questioned if the “cyber incident” would even classify as an attack, as his DDoS mitigation services sources said they did not see an attack aimed at the HHS site. The issue looked like a “spike of legitimate traffic aimed at a website of interest to the general public,” Cimpanu wrote.

However serious the incident might have been, it could be a sign of events to come in the country’s efforts to combat the coronavirus pandemic.

In the past few months, security researchers have identified a surge of phishing campaigns trying to convince people to visit malicious coronavirus-related sites, preying on fear to get their personal information. In addition, State Department officials have previously linked disinformation campaigns about the virus to a Russian operation behind “swarms of online, false personas” spreading conspiracy theories online

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West
  • New Report Says 1 in 5 SMBs Would Be Forced to Shutter After Successful Cyberattack

    Small and medium-sized businesses (SMBs) play a crucial role in the U.S. economy, making up 99.9% of all businesses and contributing to half of the nation's GDP. However, these vital economic growth drivers face an escalating threat—cyberattacks that could put them out of business. Read Now

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.