Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Attacker Infects Healthcare.gov Test Server

Federal officials say no consumer data was impacted and second open enrollment period on HealthCare.gov will not be affected.

Hackers breached a test server supporting the Obama administration's HealthCare.gov website, but did not make off with any consumer data, according to federal officials.

Security experts long have been concerned about potential security vulnerabilities in the Obama Administration's HealthCare.gov site, which got off to a rocky start last year after its launch.

In a prepared statement, Aaron Albright, a spokesperson for the Department of Health and Human Services' Centers for Medicare and Medicaid Services (CMS), says the agency's review indicates the compromised server did not contain consumers' personal information, and no data was stolen. In addition, it does not appear that the HealthCare.gov website was specifically targeted, he says.

A Wall Street Journal report says the server was compromised in July. The attacker was able to upload malware to server -- an infection that was discovered in August when the CMS security team uncovered an anomaly via the system security logs of one of the servers on the system. Further investigation found malicious files on the test server.

The malware was described as "commonplace," and was designed to launch a denial-of-service attack against other sites, as opposed to exfiltrating data. Additionally, an analysis of network traffic revealed no evidence information was sent to an external IP address.

A source with the Department of Health and Human Services reportedly told The Wall Street Journal  that the test server was protected by a default password and was never meant to be connected to the Internet.

"Like a lot of the other breaches that have made headlines over the past few months, this was the result of simple, compounded mistakes," says Eric Cowperthwaite, vice president of advanced security and strategy at Core Security. "A basic security flaw went overlooked, and it was assumed that because the system in question wasn’t supposed to be connected to the internet, it wasn’t high priority and didn’t warrant continuous monitoring. But accidently connecting a system like this to the Internet happens all the time. Complex enterprise systems are susceptible to mistakes."

Even though federal officials say no data was stolen, there are still reasons to be concerned, argues Trey Ford, global security strategist at Rapid7.

"We do not have clarity in regard to the lack of change control on the firewall, and how or why this test server was exposed to the Internet," Ford tells Dark Reading. "Finally, we do not know how many daily scans went un-reviewed -- it seems like several weeks, so this also points to a lack of attention to the Internet exposed edge of this data center."

Auditors will find production data in test environments more frequently than they’ll want to admit, he adds.

"I am very interested in learning more about how the test environment reflects production -- while we hope and trust that production systems no longer have default credentials, we also want to know that live production data is carefully managed, and does not live on a neglected test network," he says.

No matter the size of the organization, ensuring total visibility and understanding security risks is critical to protecting users, says Brad Hibbert, vice president of product strategy and operations at BeyondTrust. This includes both internal and external risks.

"Many of the latest attacks we have seen in the news target these lower priority systems where hackers gain a foothold in the environment," he says.

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
9/8/2014 | 12:00:32 PM
Re: An infection you hope to avoid
I agree with this. It created the additional damage in reputation and people would not hear test servers aspect of it, they will simply hear "the breach".
User Rank: Ninja
9/8/2014 | 11:58:48 AM
Re: Is it believable?
I agree, it is connected somewhere, such as database server, web server, application server, or any other third part interfaces to be tested. 
User Rank: Ninja
9/8/2014 | 11:56:53 AM
No internet no security

Enjoyed reading the article. Thanks for sharing it. As article points out no internet does not mean no security. There is lots of other threats coming from internal environment, more threats from inside than outside actually, we do not hear most for the inside threats and breaches.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
9/8/2014 | 9:36:28 AM
Re: An infection you hope to avoid
-- "a headline that you never want to see"

Unlikely that the headlines are going to get less frequent and the problem less critical.
User Rank: Moderator
9/8/2014 | 9:10:42 AM
Re: Is it believable?
I absolutely agree.  Just because it was a test server that wasn't supposed to connect to the internet, it doesn't change the fact that it didn't have the security controls in place.  What if it had indeed been connected to the internet and could have data siphoned off.  Or even yet, despite being a test server, I am sure it was connected to other systems.  All it takes is one server to be overlooked from a security perspective for the whole infrastructure to potentially become at risk for a breach.
User Rank: Apprentice
9/6/2014 | 1:36:01 PM
Is it believable?
Is it believable that no consumer data was impacted? How do they know for sure?

Are we to just believe them that because this was a test server it had no real data on it? Many test systems use real data to properly test things out. While it is possible that there was none it still troublesome.
Charlie Babcock
Charlie Babcock,
User Rank: Ninja
9/5/2014 | 6:46:17 PM
An infection you hope to avoid
Damage was minimal but this is still a headline that you never want to see.
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Virginia a Hot Spot For Cybersecurity Jobs
Jai Vijayan, Contributing Writer,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-10-15
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
PUBLISHED: 2019-10-15
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in...
PUBLISHED: 2019-10-15
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
PUBLISHED: 2019-10-15
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
PUBLISHED: 2019-10-15
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.