Source: www.csoonline.com – Author:
With government systems targeted in the state, Deloitte, law enforcement, and IT experts are racing to contain the breach.
Rhode Island has suffered a severe cyberattack that has potentially exposed the personal data of hundreds of thousands of residents enrolled in state-run social services programs since 2016.
Officials confirmed that RIBridges, the government system for programs like Medicaid and SNAP, was infiltrated by an international cybercriminal group. Governor Dan McKee confirmed that sensitive information — including Social Security and bank account details — has likely been stolen in the breach, which officials attribute to an international cybercriminal group.
McKee announced the breach during a news conference, revealing that hackers had planted malware capable of causing “catastrophic damage” to the system. “We understand this is alarming,” McKee said in a media statement while urging affected residents to take precautionary steps such as freezing credit and changing passwords.
The hackers breached RIBridges, the system supporting health and social services programs such as Medicaid, SNAP, and Rhode Island Works.
Officials confirmed the news following warnings from Deloitte, the system’s developer and maintainer.
“Deloitte confirmed that there is a high probability that a cybercriminal has obtained files with personally identifiable information from RIBridges,” McKee said in the statement.
The hackers are demanding a ransom as against not making the sensitive data public, AP reported quoting state officials.
The state government said in the statement that the attack has since forced them to take the portal offline, disrupting services and leaving residents and businesses on alert.
Scope of the breach
On December 5, Deloitte notified the state about a potential cyberattack targeting the RIBridges system. At that point, it was uncertain whether any sensitive information had been compromised.
Federal law enforcement, Rhode Island State Police, and relevant agencies were alerted immediately, the statement added.
Following consultation with the state IT department, Deloitte implemented additional security measures and began assessing the threat while the investigation into potential data breaches and vulnerabilities got underway. For security reasons, this information was kept internal to secure the system, the statement said.
By December 10, Deloitte confirmed that the RIBridges system had been breached, based on evidence provided by the hackers, including a screenshot of file folders. On December 11, Deloitte further determined that the implicated folders likely contained personally identifiable data from RIBridges.
“On December 13, Deloitte identified malicious code within the system, prompting the state to order the shutdown of RIBridges to address the threat,” the statement added.
Deloitte described the attack as a “major security threat” from a highly organized cybercriminal group.
“Upon learning that a state system supported by Deloitte had been attacked by an international cybercriminal group, we launched an investigation in collaboration with our client and law enforcement officials. While that investigation is ongoing, we have shown over the past decade our unwavering commitment to the State of Rhode Island and the people they serve. We will continue to work around the clock to resolve this matter,” Deloitte said in a statement.
The exact scale of the breach remains unknown, but it affects multiple RIBridges programs including Medicaid, HealthSource RI insurance, and Temporary Assistance for Needy Families (TANF).
“We are currently unaware of any identity theft or fraud related to this data breach,” McKee said in the statement. “However, we advise customers to remain vigilant and monitor their accounts for any unauthorized activity.”
To continue issuing December benefits and manage January payments, officials have switched to manual processing methods, an effort that could disrupt enrollment deadlines and delay new applications.
Impact on residents and security guidance
Governor Dan McKee and state officials have urged residents to take proactive steps to protect their financial and digital security. Affected individuals are advised to freeze their credit, strengthen passwords, and turn on multi-factor authentication.
“To the best of our knowledge, any individual who has received or applied for health coverage and/or health and human services programs or benefits could be impacted by this leak,” the statement said.
The breach coincides with HealthSourceRI’s open enrollment period, adding urgency to efforts to restore the online system. However, officials have reassured residents that updates and guidance will be provided via the state’s official cyber-alert portal.
“We are currently unaware of any identity theft or fraud related to this data breach,” McKee said in the statement. “However, we advise customers to remain vigilant and monitor their accounts for any unauthorized activity.”
A decade of challenges with RIBridges
RIBridges, originally developed in 2016 as part of the Unified Health Infrastructure Project (UHIP), has faced numerous challenges since its inception. Deloitte was paid hundreds of millions to build and maintain the system, yet it has been plagued with technical and operational issues. In the past, Deloitte had apologized publicly for the technical glitches in the system.
The state, however, renewed Deloitte’s contract in 2021 for $99 million, extending their engagement for another three years.
This latest attack has reignited concerns over the vulnerabilities in government IT systems and the need for stronger cybersecurity measures in state infrastructure. The FBI and other law enforcement agencies are actively investigating the breach, the statement added, although no further updates have been provided.
SUBSCRIBE TO OUR NEWSLETTER
From our editors straight to your inbox
Get started by entering your email address below.
Original Post url: https://www.csoonline.com/article/3625178/rhode-island-suffers-major-cyberattack-exposing-personal-data-of-thousands.html
Category & Tags: Cyberattacks, Malware, Security – Cyberattacks, Malware, Security
Views: 2