What happened
On 8 January 2019 nine employees of the Oregon Department of Human Services fell for a phishing email, giving an attacker access to their mailboxes from 9 to 28 January. About two million messages and attachments were exposed, containing information on approximately 645,000 individuals including names, addresses, dates of birth, Social Security numbers, case numbers and protected health information. Access ended when passwords were reset.
How the deception worked
A single phishing email reached staff across a large state welfare agency and nine separate employees acted on it, which is the salient fact: the message was ordinary enough that nearly a dozen people in different roles saw nothing wrong. No malware was installed at any point, so there was nothing for endpoint defences to catch. The attacker simply logged into the mailboxes with the harvested credentials and read them like any other user. The exposure was so large because caseworker mailboxes in a human services agency accumulate years of correspondence about benefit recipients, with identifiers and health details in the message bodies.
The control that would have caught it· our reading, not a claim from the sources
Multi-factor authentication would have neutralised the stolen passwords outright; mailbox retention limits would have shrunk the two million messages sitting behind them.
Sources (2)
- Phishing Attack Exposes Data of 645,000 Oregon DHS ClientsBleepingComputer·bleepingcomputer.comOpen ↗
- 645,000 Clients Affected in Oregon Department of Human Services Data BreachSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.