{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000"},"incident":{"slug":"2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000","title":"Oregon DHS phishing compromises nine employee mailboxes, exposing 645,000 clients","date":"2019-01-08","date_precision":"day","year":2019,"victim_org":"Oregon Department of Human Services","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":645000,"threat_actor":null,"summary":"On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.","how_it_worked":"A single phishing email reached staff across a large state welfare agency and nine separate employees acted on it, which is the salient fact: the message was ordinary enough that nearly a dozen people in different roles saw nothing wrong. No malware was installed at any point, so there was nothing for endpoint defences to catch. The attacker simply logged into the mailboxes with the harvested credentials and read them like any other user. The exposure was so large because caseworker mailboxes in a human services agency accumulate years of correspondence about benefit recipients, with identifiers and health details in the message bodies.","lessons":"Multi-factor authentication would have neutralised the stolen passwords outright; mailbox retention limits would have shrunk the two million messages sitting behind them.","confidence":"Confirmed","sources":[{"title":"Phishing Attack Exposes Data of 645,000 Oregon DHS Clients","url":"https://www.bleepingcomputer.com/news/security/phishing-attack-exposes-data-of-645-000-oregon-dhs-clients/","publisher":"BleepingComputer"},{"title":"645,000 Clients Affected in Oregon Department of Human Services Data Breach","url":"https://www.securityweek.com/645000-clients-affected-oregon-department-human-services-data-breach/","publisher":"SecurityWeek"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-oregon-dhs-phishing-compromises-nine-employee-mailboxes-exposing-645-000"}}