Data Breach at DC Health Insurance Exchange Ensnares US Lawmakers

A data breach at a health insurance exchange in Washington, D.C. has led a hacker to steal the personal information of US lawmakers and their staff. 

The breach hit DC Health link, which also administers healthcare plans for members of Congress. Catherine Szpindor, the Chief Administrative Officer for the House of Representatives, notified(Opens in a new window) lawmakers and their staff members about the incident on Wednesday.

“Currently, I do not know the size and scope of the breach, but have been informed by the Federal Bureau of Investigation (FBI) that account information and PII (personal identifying information) of hundreds of Member and House staff were stolen,” Szpindor wrote, according(Opens in a new window) to The Daily Caller, which was first to report the news. 

NBC News adds(Opens in a new window) that the breach also ensnared members of the US Senate, citing an email sent to Senate offices.    

A hacker who goes by the name “IntelBroker” has claimed responsibility for the breach. On Monday, the attacker began taking bids for the stolen data in a forum, saying it contained the personal information of 170,000 individuals, including their Social Security numbers, dates of birth, email addresses, and home addresses.  

The forum has since banned IntelBroker. However, another user is circulating a copy of what appears to be the same database on the open web.   

DC Health Link has confirmed the stolen data was publicly exposed on the forum. “We have initiated a comprehensive investigation and are working with forensic investigators and law enforcement,” the insurance exchange told PCMag. “Concurrently, we are taking action to ensure the security and privacy of our users’ personal information.”

Recommended by Our Editors

The exposed information could make it easy to conduct identity theft schemes on any of the individuals in the stolen database. In addition, hackers could exploit the data to try to deliver phishing messages to the personal email addresses of lawmakers and their staff, which could put national security in jeopardy.

In response, DC Health Link says it’ll provide free identity and credit monitoring services to all its customers. “The investigation is still ongoing and we will provide more information as we have more to share,” it added.

SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.”,”first_published_at”:”2021-09-30T21:22:09.000000Z”,”published_at”:”2022-03-24T14:57:33.000000Z”,”last_published_at”:”2022-03-24T14:57:28.000000Z”,”created_at”:null,”updated_at”:”2022-03-24T14:57:33.000000Z”})” x-show=”showEmailSignUp()” class=”rounded bg-gray-lightest text-center md:px-32 md:py-8 p-4 mt-8 container-xs” readability=”31.423799582463″>

Like What You’re Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.

Facebook Comments Box

Hits: 0