Hackers Broke Into Server for Obamacare Website, Say Officials

Advertisement
By Reuters | Updated: 5 September 2014 12:31 IST
An unknown hacker or hackers broke into a computer server supporting the HealthCare.gov website through which consumers enroll in Obamacare health insurance, a government cyber-security team discovered last week, apparently uploading malicious files.

The Centers for Medicare and Medicaid Services, the lead Obamacare agency, briefed key congressional staff on Thursday about the intrusions, the first of which occurred on July 8, CMS spokesman Aaron Albright said.

The malware uploaded to the server was designed to launch a distributed denial of service, or DDoS, attack against other websites, not to steal personal information, Albright said.

Advertisement

In a DDoS, Internet-connected computers are so overwhelmed by malware attempting to communicate with their website that, unable to handle legitimate requests, they crash.

"Our review indicates that the server did not contain consumer personal information; data was not transmitted outside the agency, and the website was not specifically targeted," Albright said. "We have taken measures to further strengthen security."

Advertisement

Albright said the attack would have no impact on the second open enrollment period for Obamacare, which begins on Nov. 15.

The Office of Inspector General of the Department of Health and Human Services, CMS's parent agency, and HHS leadership were notified of the attack, which was first reported by the Wall Street Journal.

Advertisement

Representative Diane Black of Tennessee, a longtime Republican critic of Obamacare, criticized CMS for the breach, saying: "Designing a secure website should have been a top priority for this administration."

Republican Darrell Issa, chairman of the House of Representatives Oversight and Government Reform Committee, said the committee would seek answers from CMS Administrator Marilyn Tavenner at a hearing on Sept. 18.

Advertisement

A spokesman for the Department of Homeland Security, which helps investigate cyber attacks, said its Computer Emergency Readiness Team, or US-CERT, had forensically preserved the affected server and had identified and extracted the malware designed to launch a denial of service attack.

US-CERT analysis indicated that only one server was involved. It was not running HealthCare.gov, but was instead used by programmers to test new code before it goes live.

The test server was not supposed to be connected to the Internet, but somehow was. In addition, access to it was protected by a default password installed by the manufacturer, said Albright, who declined to say if that default was 1-2-3-4-5 or something equally breachable.

Cyber-security expert David Kennedy, chief executive of the information security firm TrustedSec LLC, said he was unconvinced this was the first successful hack on HealthCare.gov.

"There are fundamental flaws in how they're coding the website and it's going to take a long, long time to fix it," he told Reuters. "It continues to be a really big glaring security hole."

It is rare for hackers to upload malware without following through to use it, he added.

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 FE Roundup: Expected Price in India, Specifications
  2. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  3. Redmi Pad 2 SE 4G Debuts With 9.7-Inch Display, 7,600mAh Battery: See Price
  4. Redmi K90 Max Debuts With Active Cooling Fan, 8,550mAh Battery: See Price
  5. iPhone 18 May Not Arrive With Hardware Upgrades as Apple Cuts Costs: Report
  6. Oppo Enco Clip 2 With Open-Ear Design, Launched Alongside Oppo Watch X3 Mini
  7. Redmi Buds 8 Launched With Up to 50dB ANC, Up to 44 Hours Total Battery Life
  8. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  9. Motorola Edge 70 Fusion Review
  10. WhatsApp Plus Subscription: What Is It, Pricing, Features and Benefits
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.