Site icon THE CHESAPEAKE TODAY

Maryland: State Agencies Threatened by Cyberattacks

Spread the love

<p><a href&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;&sol;wp-content&sol;uploads&sol;2014&sol;05&sol;Patrol-car-computer-St&period;-Marys-Sheriff&period;jpg"><img class&equals;"alignleft size-medium wp-image-4221" src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;&sol;wp-content&sol;uploads&sol;2014&sol;05&sol;Patrol-car-computer-St&period;-Marys-Sheriff-300x224&period;jpg" alt&equals;"Patrol car computer St&period; Mary's Sheriff" width&equals;"300" height&equals;"224" &sol;><&sol;a><&sol;p>&NewLine;<p><strong>By <&sol;strong><a title&equals;"Posts by Mike Denison" href&equals;"http&colon;&sol;&sol;cnsmaryland&period;org&sol;author&sol;mdenison91&sol;" rel&equals;"author"><strong>Mike Denison<&sol;strong><&sol;a><br &sol;>&NewLine;<strong><em>Capital News Service<&sol;em><&sol;strong><&sol;p>&NewLine;<p>ANNAPOLIS – Maryland government entities have suffered at least six cyberattacks since the beginning of 2013&comma; according to incident reports from the Department of Information Technology&period;<&sol;p>&NewLine;<p>The heavily redacted reports&comma; obtained by Capital News Service through a Maryland Public Information Act request&comma; reveal that data-hungry hackers and scammers aren’t only going after retailers like Target and Neiman Marcus — they’re targeting state agencies&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;Our government doesn’t move as quickly as the private sector … and the private sector isn’t moving as quickly as it should be&comma;” Sen&period; Catherine Pugh&comma; D-Baltimore&comma; said in an interview&period;<&sol;p>&NewLine;<p><a href&equals;"http&colon;&sol;&sol;cnsmaryland&period;org&sol;wp-content&sol;uploads&sol;2014&sol;04&sol;sen-pugh-resized&period;jpg"><img class&equals;"size-medium wp-image-21161" src&equals;"http&colon;&sol;&sol;cnsmaryland&period;org&sol;wp-content&sol;uploads&sol;2014&sol;04&sol;sen-pugh-resized-300x167&period;jpg" alt&equals;"" width&equals;"300" height&equals;"167" &sol;><&sol;a><&sol;p>&NewLine;<p>The report said a phishing scam that hit the Department of Labor&comma; Licensing and Regulation affected &OpenCurlyDoubleQuote;more than 100 users&comma;” and two other incidents affected an estimated &OpenCurlyDoubleQuote;more than 10 users&period;”<&sol;p>&NewLine;<p>Elliot Schlanger&comma; the state director of cybersecurity&comma; said specific numbers of affected users are often difficult to pin down&comma; particularly with phishing attacks&period; Phishing involves sending a large number of emails asking for sensitive information&comma; like passwords&comma; under the guise of a legitimate sender&period;<&sol;p>&NewLine;<p>One incident on the report involved the Maryland State Police in September&period; Last year&comma; the police were bombarded with thousands of gun applications ahead of incoming stricter firearm laws&period; To reduce the massive backlog&comma; volunteers from the departments of <strong>Health and Mental Hygiene&comma; Transportation&comma; Public Safety and Correctional Services&comma; Human Resources and Juvenile Services<&sol;strong> offered to help out with data entry&comma; according to a police press release&period;<&sol;p>&NewLine;<p>According to a <strong>National Rifle Association<&sol;strong> press release&comma; some state agencies’ computers were not adequately secured to handle gun applications&comma; which include sensitive information&period;<&sol;p>&NewLine;<p>Elena Russo&comma; director of the police’s communications department&comma; said the incident on the Department of Information Technology report was merely a notification of a potential security risk&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;It was not a security breach&comma; it was not a cyber breach&comma; there were no hacks and no data brought forward by the Maryland State Police&comma;” she said&period;<&sol;p>&NewLine;<p>Similarly&comma; <strong>Maureen O’Connor&comma; director of media relations for the Department of Labor Licensing and Regulation<&sol;strong>&comma; said that no personnel data was stolen in a phishing attack on her department&period; However&comma; a malicious program known as a &OpenCurlyDoubleQuote;ransomware” encrypted department information&comma; demanding that money be sent to a specific account to unlock the data&period;<&sol;p>&NewLine;<p>The attack began when an employee ignored a department-wide warning not to open a suspicious email&period; O’Connor said the malware was eliminated and the data restored within four days&period;<&sol;p>&NewLine;<p>The document also said that three Department of Human Resources servers were attacked on Oct&period; 22&period; Brian Schleter&comma; director of communications for the agency&comma; said the attack was launched on a department website used to post press releases&period; No data was compromised&period;<&sol;p>&NewLine;<p>The proposed budget for fiscal year 2014 notes that no &OpenCurlyDoubleQuote;substantial disruptions” of state network services have occurred since 2011&comma; when records of disruptions began&period;<&sol;p>&NewLine;<p>The state has taken steps to teach its employees about best practices in cybersecurity&period; In February&comma; Isabel FitzGerald&comma; secretary of the Department of Information Technology&comma; told the House of Delegates that the department had begun monthly cybersecurity training courses for more than 40&comma;000 state employees and contractors&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;They endeavor to make sure all the employees of all the agencies are aware of the possibilities of attacks&comma;” said O’Connor&comma; who has taken the course&period;<&sol;p>&NewLine;<p>The state’s vulnerabilities aren’t new&period; The <strong>Office of Legislative Audits<&sol;strong> has outlined weaknesses in many agencies’ cybersecurity plans over several years&period; An audit of the state police from February 2009 to December 2011 found that some servers that guarded personal information&comma; including about 176&comma;000 Social Security numbers&comma; were insufficiently secured&period; In a March 2013 response to the audit&comma; the police insisted the auditors misunderstood a security measure&comma; and personal information was secure&period;<&sol;p>&NewLine;<p>The audit also found that police networks lacked systems designed to detect intrusions&period; The response said that those systems were added after the audit&period;<&sol;p>&NewLine;<p>Similar audits found more cyber vulnerabilities in the departments of Labor&comma; Transportation and Education as well as the State Archives&period;<&sol;p>&NewLine;<p>Pugh aimed to promote state cybersecurity even further during the recently-ended 2014 legislative session&period; She authored a bill to adopt an overarching cybersecurity plan based on a similar document published by the National Institute of Standards and Technology&period; The Senate passed the bill unanimously&comma; but it died in the House of Delegates in committee&period;<&sol;p>&NewLine;<p>Pugh said the bill arose out of concerns for the state’s long-term condition&comma; citing the growing amount of information that state entities and contractors transfer online&period; A 2012 hack into South Carolina records that exposed 3&period;6 million tax returns&comma; according to the South Carolina Department of Revenue&comma; encouraged her to make sure Maryland didn’t suffer a similar fate&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;If this can occur in other states&comma; it can occur here&comma;” Pugh said&period;<&sol;p>&NewLine;<p>While the Department of Information Technology’s information security policy currently encourages following National Institute of Standards and Technology recommendations&comma; Pugh said that her bill would have given state departments incentive to ensure they were actually following best practices&period;<&sol;p>&NewLine;<p>Costis Toregas&comma; a computer science professor at The George Washington University&comma; warned that the government reports may not tell the full story&period; He said that there are &OpenCurlyDoubleQuote;probably hundreds of thousands” of attempted attacks on Maryland agencies every day that don’t get public attention&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;We penalize people for coming forward and saying something bad happened…there’s no sharing of information happening&comma;” he said&period;<&sol;p>&NewLine;<p>According to state information technology policy&comma; agencies do not need to report viruses or malware that have been automatically thwarted by anti-virus software&period;<&sol;p>&NewLine;<p>The Heartbleed security bug&comma; first discovered on April 7&comma; also may have a serious impact on government operations&period; The bug is a vulnerability in OpenSSL&comma; a security protocol used to protect information on about two-thirds of all web servers&comma; according to the technology website Ars Technica&period; Hackers can exploit the bug to steal passwords and other sensitive information&period;<&sol;p>&NewLine;<p>Toregas said even if they aren’t vulnerable to <strong>Heartbleed<&sol;strong> on their own&comma; state agencies could still be seriously affected by it if they interact with vulnerable businesses&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;We live in an interconnected world&period; At some point the government will come into contact with a commercial entity on the web&comma;” Toregas said&period; &OpenCurlyDoubleQuote;We’ve become too interconnected to draw a rigid line between commercial &lbrack;and government entities&rsqb;&period;”<&sol;p>&NewLine;<p>Schlanger said after the Heartbleed outbreak&comma; the <strong>Department of Information Technology<&sol;strong> shared strategies to deal with the bug with state information officers&comma; some of which may have affected users&period; He added that the department would continue to keep tabs on potential fallout from the bug&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;Continuous monitoring of the cyber threatscape is one of the fundamental tenets of our cybersecurity program&comma;” Schlanger wrote in an email&period;<&sol;p>&NewLine;<p>The Department of Information Technology report also included three incidents that were not cyberattacks&comma; in addition to the police’s risk warning&period; These included a stolen computer&comma; a former employee sending an email from another’s account&comma; and an employee’s home computer being infected with<strong> malware<&sol;strong>&period;<&sol;p>&NewLine;<p>What the phishers and would-be hackers were looking for in state agency computers remains a mystery&period; Mark Cather&comma; director of communications and security at the <strong>University of Maryland&comma; Baltimore County<&sol;strong>&comma; said they were likely seeking employees’ personal information &OpenCurlyDoubleQuote;because they can turn identities into cash&period;”<&sol;p>&NewLine;<p>Hackers might also have tried to use government computers as a resource&comma; utilizing their processing power to crunch numbers or launch further attacks&comma; Cather said&period; He added that some may have sought trade secrets or other information worth selling&comma; but it was unlikely because few state agencies make anything with patents or trademarks that would be worth selling&period;<&sol;p>&NewLine;<p>Regardless of their objectives&comma; hackers aren’t going to leave state agencies alone anytime soon&period; Pugh hopes that legislators will take a more active role in promoting cybersecurity&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;I look at the government from the perspective of a business&comma;” Pugh said&period; &OpenCurlyDoubleQuote;…What do want the state to look like three years from now&quest; I don’t think we do enough of that kind of thinking and planning&period;”<&sol;p>&NewLine;<h2 class&equals;"left&lowbar;heading ">About the Author<&sol;h2>&NewLine;<div class&equals;"author ">&NewLine;<div class&equals;"icon"><img class&equals;" avatar avatar-75 photo user-182-avatar" src&equals;"http&colon;&sol;&sol;cnsmaryland&period;org&sol;wp-content&sol;plugins&sol;user-avatar&sol;user-avatar-pic&period;php&quest;src&equals;http&colon;&sol;&sol;cnsmaryland&period;org&sol;wp-content&sol;uploads&sol;avatars&sol;182&sol;1397051470-bpfull&period;jpg&amp&semi;w&equals;75&amp&semi;id&equals;182&amp&semi;random&equals;1397051470" alt&equals;"" width&equals;"75" height&equals;"75" &sol;><&sol;p>&NewLine;<div class&equals;"title"><a title&equals;"Posts by Mike Denison" href&equals;"http&colon;&sol;&sol;cnsmaryland&period;org&sol;author&sol;mdenison91&sol;" rel&equals;"author">Mike Denison<&sol;a><&sol;div>&NewLine;<p><&excl;-- &num;title --><&sol;div>&NewLine;<p><&excl;-- &num;icon --><&sol;p>&NewLine;<div class&equals;"authorcontent">&NewLine;<p>Mike Denison is a senior in the University of Maryland Philip Merrill College of Journalism&comma; covering science&comma; technology and health care in Annapolis&period; He has interned with <a href&equals;"http&colon;&sol;&sol;www&period;usatoday&period;com&sol;">USA Today<&sol;a>&comma; where he assisted in managing the web site&&num;8217&semi;s News section&comma; and <a href&equals;"http&colon;&sol;&sol;www&period;thedailyrecord&period;com&sol;">The Daily Record<&sol;a>&comma; where he covered business news in the Baltimore area&period; Follow him on Twitter <a href&equals;"http&colon;&sol;&sol;www&period;twitter&period;com&sol;mdenison91">&commat;mdenison91<&sol;a>&period;<&sol;p>&NewLine;<div id&equals;"metaslider-id-3609" style&equals;"max-width&colon; 750px&semi;" class&equals;"ml-slider-3-100-1 metaslider metaslider-flex metaslider-3609 ml-slider ms-theme-default" role&equals;"region" aria-label&equals;"Advertisers" data-height&equals;"500" data-width&equals;"750">&NewLine; <div id&equals;"metaslider&lowbar;container&lowbar;3609">&NewLine; <div id&equals;"metaslider&lowbar;3609" class&equals;"flexslider">&NewLine; <ul class&equals;'slides'>&NewLine; <li style&equals;"display&colon; block&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-11695 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2016-08-03 00&colon;11&colon;16"><a href&equals;"https&colon;&sol;&sol;www&period;facebook&period;com&sol;lindascafelpcity&sol;" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2016&sol;08&sol;Lindas-On-The-Go-side-604x403&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-11695 msDefaultImage" &sol;><&sol;a><div class&equals;"caption-wrap"><div class&equals;"caption">One incident on the report involved the Maryland State Police in September&period; Last year&comma; the police were bombarded with thousands of gun applications ahead of incoming stricter firearm laws&period; To reduce the massive backlog&comma; volunteers from the departments of Health and Mental Hygiene&comma; Transportation&comma; Public Safety and Correctional Services&comma; Human Resources and Juvenile Services offered to help out with data entry&comma; according to a police press release&period;&NewLine;&NewLine;According to a National Rifle Association press release&comma; some state agencies’ computers were not adequately secured to handle gun applications&comma; which include sensitive information&NewLine;<&sol;div><&sol;div><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-1464 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2011-04-03 01&colon;26&colon;27"><a href&equals;"http&colon;&sol;&sol;allpawnandguns&period;com&sol;" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2011&sol;04&sol;All-Pawn-March-2011-Ches-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-1464 msDefaultImage" &sol;><&sol;a><div class&equals;"caption-wrap"><div class&equals;"caption">One incident on the report involved the Maryland State Police in September&period; Last year&comma; the police were bombarded with thousands of gun applications ahead of incoming stricter firearm laws&period; To reduce the massive backlog&comma; volunteers from the departments of Health and Mental Hygiene&comma; Transportation&comma; Public Safety and Correctional Services&comma; Human Resources and Juvenile Services offered to help out with data entry&comma; according to a police press release&period;&NewLine;&NewLine;According to a National Rifle Association press release&comma; some state agencies’ computers were not adequately secured to handle gun applications&comma; which include sensitive information&NewLine;<&sol;div><&sol;div><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-15651 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2019-05-28 19&colon;45&colon;10"><a href&equals;"https&colon;&sol;&sol;read&period;amazon&period;com&sol;kp&sol;embed&quest;asin&equals;B07S8F7WF6&amp&semi;preview&equals;newtab&amp&semi;linkCode&equals;kpe&amp&semi;ref&lowbar;&equals;cm&lowbar;sw&lowbar;r&lowbar;kb&lowbar;dp&lowbar;NqC7CbPH5FBPA&amp&semi;tag&equals;stmarystodaonlin" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2019&sol;05&sol;MurderUSA&lowbar;AUDIO-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-15651 msDefaultImage" title&equals;"boy screams opening the mouth" &sol;><&sol;a><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-16578 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2021-05-07 14&colon;29&colon;41"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2021&sol;05&sol;Buzzs-Marina-2019-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-16578 msDefaultImage" title&equals;"Buzzs Marina 2019" &sol;><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-16742 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2021-10-24 22&colon;51&colon;01"><a href&equals;"https&colon;&sol;&sol;www&period;facebook&period;com&sol;lindascafelpcity" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2024&sol;02&sol;Lindas-Cafe-Now-Open-at-new-location-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-16742 msDefaultImage" title&equals;"Lindas Cafe Now Open at new location" &sol;><&sol;a><div class&equals;"caption-wrap"><div class&equals;"caption"><div>Linda's Cafe new location now open<&sol;div><&sol;div><&sol;div><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-16901 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2022-01-15 22&colon;19&colon;57"><a href&equals;"http&colon;&sol;&sol;floridafishingkayaks&period;com&sol;" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2022&sol;01&sol;Wavewalk-Kayaks-1-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-16901 msDefaultImage" title&equals;"Wavewalk Kayaks" &sol;><&sol;a><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-17596 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2023-08-11 22&colon;30&colon;44"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2023&sol;08&sol;Press-pass-OConnor-email-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-17596 msDefaultImage" title&equals;"Press pass O&&num;039&semi;Connor email" &sol;><div class&equals;"caption-wrap"><div class&equals;"caption"><div>WHISTLE BLOWERS WANTED<&sol;div><&sol;div><&sol;div><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-17916 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2024-08-03 21&colon;43&colon;22"><a href&equals;"https&colon;&sol;&sol;www&period;huntplumbingheatingandairconditioning&period;com&sol;" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2024&sol;08&sol;HUNT-Plumbing-Heating-and-Air-Conditioning-750x500&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-17916 msDefaultImage" title&equals;"HUNT Plumbing Heating and Air Conditioning" &sol;><&sol;a><div class&equals;"caption-wrap"><div class&equals;"caption"><div>Click to website for Special Offers<&sol;div><&sol;div><&sol;div><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-28836 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2024-11-06 20&colon;52&colon;51"><a href&equals;"https&colon;&sol;&sol;www&period;amazon&period;com&sol;dp&sol;B0D17J3VS7&quest;binding&equals;kindle&lowbar;edition&amp&semi;ref&lowbar;&equals;dbs&lowbar;s&lowbar;ks&lowbar;series&lowbar;rwt&lowbar;tkin&amp&semi;qid&equals;1730944414&amp&semi;sr&equals;1-2" target&equals;"&lowbar;blank" aria-label&equals;"View Slide Details" class&equals;"metaslider&lowbar;image&lowbar;link"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;32-Book-Series-THE-CHESAPEAKE-TODAY--381x254&period;png" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-28836 msDefaultImage" title&equals;"32 Book Series THE CHESAPEAKE TODAY" &sol;><&sol;a><&sol;li>&NewLine; <li style&equals;"display&colon; none&semi; width&colon; 100&percnt;&semi;" class&equals;"slide-28898 ms-image " aria-roledescription&equals;"slide" data-date&equals;"2025-05-12 08&colon;27&colon;53"><img src&equals;"https&colon;&sol;&sol;www&period;the-chesapeake&period;com&sol;wp-content&sol;uploads&sol;2025&sol;05&sol;FITZIES-IS-BACK-FOR-2025-556x370&period;jpg" height&equals;"500" width&equals;"750" alt&equals;"" class&equals;"slider-3609 slide-28898 msDefaultImage" title&equals;"FITZIES IS BACK FOR 2025" &sol;><&sol;li>&NewLine; <&sol;ul>&NewLine; <&sol;div>&NewLine; &NewLine; <&sol;div>&NewLine;<&sol;div>&NewLine;<&sol;div>&NewLine;<&sol;div>&NewLine;

Spread the love
Exit mobile version