BALTIMORE COUNTY, MARYLAND ADDRESSES PBI RESEARCH SERVICES MOVEIT INCIDENT
Breach Type –
Unknown, Data Breach
BaltimoreCountyMd.gov
August 11th, 2023
- "Baltimore County announced that it has been notified by third party vendor PBI Research Services (“PBI”) of a recent security incident involving “MOVEit,” a file transfer software program hosted by PBI. The County, one of numerous entities affected nationwideexternal link, is coordinating with PBI to take steps to address this incident.”
- ”PBI notified Baltimore County on June 14, 2023, that some of the files the County shared with PBI may have been subject to unauthorized access and download. According to PBI, a technical vulnerability in the file transfer program, MOVEit, may have allowed unauthorized parties to access and download files between May 29, 2023, and May 30, 2023.”
- ”After learning of the incident, PBI launched an internal investigation using leading cybersecurity and digital forensics specialists. PBI also notified federal law enforcement on June 3, 2023 and began to identify the individuals whose information may have been contained in the files involved in the incident. Through their investigation, PBI determined that certain individuals’ PII, including first and last names, dates of birth, addresses, and Social Security numbers may have been involved.”
Read More
Maryland Urges Identity Protection Following Major Cyber Attack, Anne Arundel County
Breach Type –
Hacking, Data Breach
Southern Maryland Chronicle
June 21st, 2023
- “Maryland officials urge residents to implement identity protection measures in response to a vast cyber-attack. The Maryland Department of Human Services is among an unspecified number of national organizations that were victims of the MOVEit data breach, believed to be linked to a security loophole in a file transfer tool. The breach occurred at a third-party vendor engaged by the state."
- “At this juncture, no signs indicate that any purloined data has been sold, used, disseminated, or disclosed, nor has the State of Maryland received any contact from the culprits.”
- ”State agency IT points of contact, emergency coordinators, and local emergency managers have been advised to heed the advisory issued by the federal Cybersecurity and Infrastructure Security Agency. They are expected to install any necessary patches to counter possible vulnerabilities with the assistance of the Department of Information Technology.”
Read More
Worcester Co. Addresses Government Email Breach, Worcester County
Breach Type – Phishing, Data Breach
WGMD 92.7
April 29th, 2022
- “Worcester County has discovered a breach of the county government email account which contained limited personal information belonging to about 3,000 government and board of education employee and retiree accounts."
- "Cybersecurity professionals discovered the breach while conducting a forensic investigation into a phishing incident that occurred between November 10th and November 20th, 2020."
- "Worcester County Government said Thursday that it has implemented significant security measures to protect everyone who has been impacted, but there is no forensic evidence that any information that was accessed has been misused."
- “Anyone whose information has been affected has been advised to be vigilant, review accounts for any fraudulent activity or statements, and to order a free credit report."
Read More
Prince George's government affected by ransomware attack, Prince George’s County
Breach Type – Hacking, Ransomware
Washington Post
December 14th, 2021
- "Prince George’s County government has been affected by a national ransomware attack on Ultimate Kronos Group"
- “the ransomware does not impact the county government’s payroll but does impact its timekeeping function. She said that to ensure employees are paid on time, staff and supervisors will be required to keep time both offline in the vendor system and manually."
- “County government leadership have been working diligently to understand the scope of this ransomware attack, and how it affects our government,”
- “We will continue to seek answers from the vendor and put in place temporary procedures while Kronos works through this matter.”
Read More
Cyberattack Freezes Maryland Health Department, State of Maryland
Breach Type – Unknown, Malware
Washington Post
December 5th, 2021
- “A cyberattack took Maryland’s health department offline this weekend, as officials worked to assess the extent of the intrusion.”
- “The Maryland Security Operations Center is investigating a network security incident involving the Maryland Department of Health,” Andy Owen, a department spokesman, said in a statement to The Washington Post. “Certain systems have been taken offline out of an abundance of caution and other precautions have and will be taken.”
- “Owen said that state officials were coordinating with federal and state law enforcement, and that the investigation is ongoing. He declined to say whether the state’s response to the coronavirus pandemic had been affected by the cyberattack….”
- “The Department of Health’s webpage on Sunday was rerouted to the state’s flagship webpage, www.maryland.gov, as officials went through individual systems to determine whether any information had been stolen.”
Read More
CBS Local News Baltimore
January 12th 2022
-
“In early December, the state health department was unable to report COVID-19 data following a cyberattack. The agency attributed the lack of updates to a “server outage.”
- “By Dec. 10, state health officials were able to report some COVID-19 data, such as hospitalizations, but all the topline metrics were not fully restored until Dec. 20, following a two-week hiatus.”
-
“The state government did not pay the ransom demand, Stewart said.”
-
“In a Jan. 11 update, the state health department said it had restored 95% of state-level data following the “network security incident.”
Read More
Global Ransomware Attack Takes Leonardtown Offline, St. Mary’s County
Breach Type –
Hacking, Ransomware
Washington Post
July 8th, 2021
- “Everything shut down,” she said in an interview. “You couldn’t open any document, you’re completely locked from all your files."
- -"McKay learned later that day that the town had been a victim of the massive ransomware attack that breached a popular software made by the information technology company Kaseya. The attack reached Leonardtown through its IT management company, JustTech, which uses the affected Kaseya product…"
- ”McKay learned later that day that the town had been a victim of the massive ransomware attack that breached a popular software made by the information technology company Kaseya. The attack reached Leonardtown through its IT management company, JustTech, which uses the affected Kaseya product.”
- “McKay learned later that day that the town had been a victim of the massive ransomware attack that breached a popular software made by the information technology company Kaseya. The attack reached Leonardtown through its IT management company, JustTech, which uses the affected Kaseya product.”
Read More
Digital Management Inc., Montgomery County
Breach Type –
Hacking, Ransomware
ZD Net
June 3rd, 2020
-
Cybersecurity company was hit in ransomware cyberattack
-
NASA files were accessed during the attack
-
Bad actor group claimed over 2,500 servers and PCs were encrypted
Read More
St. Mary’s County Health Department, St. Mary’s County
Breach Type –
Hacking, Malware
The Bay Net
April 24th, 2020
-
Health center was victim of malware cyberattack
-
State IT department assisted with investigation
-
Officials stated that cyberattack won't affect COVID-19 response
Read More
Southern Maryland Newspapers Online
April 29th, 2020
-
Despite official's statement, cyberattack hampered COVID-19 response
-
Health center's mapping of Coronavirus cases remained unfixed
-
State IT personnel worked to fully restore health center's services
Read More
National Institutes of Health (NIH), Montgomery County
Breach Type –
Hacking, Data Breach
MSN
April 21st, 2020
-
25,000 email addresses and passwords were leaked during cyberattack
-
Victims included National Institutes of Health and the World Health Organization
-
Majority of emails and passwords stolen were from the NIH
Read More
Defense Information Systems Administration, Anne Arundel County
Breach Type -
Hacking, Data Breach
Data Breaches
February 20th, 2020
-
Federal intelligence agency hit in hacking cyberattack
-
Officials believed the attack was of epic proportions
-
Personal identification information was likely stolen
Read More
Dorchester County Government Systems, Dorchester County
Breach Type –
Unknown, Ransomware
Dorchester Banner
January 28th, 2020
-
Bad actors demanded Bitcoin ransom
-
Ransomware cyberattack used against county government
-
Federal authorities assisted in investigation
Read More
Maryland Department of Labor
Breach Type – Hacking, Data Breach
Washington Post
July 5th, 2019
- 2 older Maryland state databases were accessed by hackers who were able to see names and social security numbers of 78,000 people
- People impacted by the breach included those who received unemployment benefits in 2012 and those who sought a general equivalency diploma in 2009, 2010 or 2014
- Those impacted were notified and an independent company’s investigation found no evidence of hackers downloading data
Read More
City of Baltimore Government Systems, Baltimore City County
Breach Type - Ransomware
U.S. News
May 7th, 2019
- The government of Baltimore was forced to shut down most of its systems following a ransomware virus
- No critical systems were compromised and no sensitive personal information has been exposed
- Email and phone systems did compromise the effectiveness of operations within the networks
Read More
State Scoop
May 7th, 2019
- The malware was identified as RobinHood that is a new ransomware variant
- This specific ransomware variant has an unknown origin of how it went into the City’s network
- An aggressive note had been found that was in broken English
Read More
Anne Arundel County Library, Anne Arundel County
Breach Type - Phishing, Malware
Capital Gazette
October 7th, 2018
- 600 Anne Arundel County Library computers exposed & infected with Emotet virus
- Library customer information was not breached
- Emails containing the Emotet virus may have circulated, impersonating PayPal
Read More
Caroline County Government, Caroline County
Breach Type - Phishing, Data Breach
Caroline MD
March 1st, 2018
- Caroline County fell victim to phishing attack
- Hackers impersonated County Administrator
- W-2 forms were sent to hackers
- All 2017 county employees affected by data breach
Read More
Frederick County
Breach Type - Cryptojack/Other
WCCF Tech
February 12th, 2018
- Over 4,200 victims hijacked to mine Monero cryptocurrency
- Secretly hijacked using compromised plug-in called "Browsealoud"
- Though sites were affected for hours, no user data was affected/compromised
Read More
Maryland State Election System
Breach Type - Russian Election Hacking
CyberScoop
September 22nd, 2017
- Department of Homeland Security notifies 21 states of Russian election hacking
- Intrusion occurred in 2016 – taking officials 1 year to notify states including MD
- Serious attempts to compromise states did not result in vote tallies being affected
Read More
StateScoop
April 16th, 2018
- Most of the 21 originally notified states believed to be scanned by hackers
- Vote tallies remain unaffected for 2016 elections
- Allocating federal funding to cyber security related election efforts
Read More
Howard County Website
Breach Type - Hacking
Baltimore Sun
June 26th, 2017
- Government website hacked with pro-Islamic State messages
- Part of a larger attack on local gov. websites
- No breach of data
- No personal data compromised
Read More
Baltimore City Employees
Breach Type - Hacking
Baltimore Sun
April 14th, 2016
- Hacker stole data from Baltimore City employees and filed fraudulent tax returns
- Not clear how many employees affected or when attack occurred
Read More
BACK TO TOP