Hackers Broke Into Server for Obamacare Website, Say Officials

Advertisement
By Reuters | Updated: 5 September 2014 12:31 IST
An unknown hacker or hackers broke into a computer server supporting the HealthCare.gov website through which consumers enroll in Obamacare health insurance, a government cyber-security team discovered last week, apparently uploading malicious files.

The Centers for Medicare and Medicaid Services, the lead Obamacare agency, briefed key congressional staff on Thursday about the intrusions, the first of which occurred on July 8, CMS spokesman Aaron Albright said.

The malware uploaded to the server was designed to launch a distributed denial of service, or DDoS, attack against other websites, not to steal personal information, Albright said.

In a DDoS, Internet-connected computers are so overwhelmed by malware attempting to communicate with their website that, unable to handle legitimate requests, they crash.

Advertisement

"Our review indicates that the server did not contain consumer personal information; data was not transmitted outside the agency, and the website was not specifically targeted," Albright said. "We have taken measures to further strengthen security."

Albright said the attack would have no impact on the second open enrollment period for Obamacare, which begins on Nov. 15.

The Office of Inspector General of the Department of Health and Human Services, CMS's parent agency, and HHS leadership were notified of the attack, which was first reported by the Wall Street Journal.

Advertisement

Representative Diane Black of Tennessee, a longtime Republican critic of Obamacare, criticized CMS for the breach, saying: "Designing a secure website should have been a top priority for this administration."

Republican Darrell Issa, chairman of the House of Representatives Oversight and Government Reform Committee, said the committee would seek answers from CMS Administrator Marilyn Tavenner at a hearing on Sept. 18.

Advertisement

A spokesman for the Department of Homeland Security, which helps investigate cyber attacks, said its Computer Emergency Readiness Team, or US-CERT, had forensically preserved the affected server and had identified and extracted the malware designed to launch a denial of service attack.

US-CERT analysis indicated that only one server was involved. It was not running HealthCare.gov, but was instead used by programmers to test new code before it goes live.

Advertisement

The test server was not supposed to be connected to the Internet, but somehow was. In addition, access to it was protected by a default password installed by the manufacturer, said Albright, who declined to say if that default was 1-2-3-4-5 or something equally breachable.

Cyber-security expert David Kennedy, chief executive of the information security firm TrustedSec LLC, said he was unconvinced this was the first successful hack on HealthCare.gov.

"There are fundamental flaws in how they're coding the website and it's going to take a long, long time to fix it," he told Reuters. "It continues to be a really big glaring security hole."

It is rare for hackers to upload malware without following through to use it, he added.

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. CMF Headphone Pro With Up to 100 Hours of Battery Life Launched: See Price
  2. Sandisk Launches Creator Series Storage Devices in India: Price, Details
  3. Flipkart Big Billion Days Sale: Top Deals Before It Ends on This Date
  4. YouTube Premium Lite is Now Available in India at This Price
  5. Five Reasons Why Samsung Galaxy S24 Ultra is The Biggest Deal of 2025
  6. Sony Finally Launches Its WH-1000XM6 Wireless Headphones in India: See Price
  7. Top Deals on Laptops Under Rs. 60,000 During Amazon Great Indian Festival
  8. War 2 OTT Release Date: When and Where to Watch To Watch Hrithik Roshan Starrer Action Mov
  9. Samsung Galaxy S26 Ultra Could Feature This Chipset and Camera
  1. ChatGPT Now Lets Users Shop Without Leaving the Chat Window With New Instant Checkout Feature
  2. Moto X70 Air Launch Timeline Confirmed; Could Rival iPhone Air, Samsung Galaxy S25 Edge With Slim Profile
  3. Apple Releases iOS 26.0.1 Update With Fixes for Bluetooth, Camera, and Cellular Issues on iPhone 17 and iPhone Air
  4. WhatsApp Announces Support for Sharing Live Photos, Meta AI-Powered Chat Themes, New Sticker Packs, and More
  5. Physicists Identify Loophole in Heisenberg’s Uncertainty Principle While Preserving Its Validity
  6. SpaceX’s Falcon 9 Lifts Off Successfully From Vandenberg Space Force Base
  7. NASA Faces Uncertainty Over Space Plane Missions to ISS Before Its Deorbit
  8. SpaceX Falcon 9 Deploys 28 Next-Generation Starlink V2 Mini Satellites
  9. How To Train Your Dragon OTT Release Date: When and Where to Watch This Live Action Movie Online?
  10. War 2 OTT Release Date: When and Where to Watch To Watch Hrithik Roshan Starrer Action Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.