Data leak

Washington D.C. Health Benefit Exchange Breach β€” 56,000 Legislators and Staff

πŸ“… 2023-03-08 🏒 DC Health Benefit Exchange Authority enrollment system
Primary Source β†—

Incident Details

In March 2023, data for approximately 56,415 individuals enrolled in DC Health Link β€” the health insurance marketplace for Washington D.C. residents including US House of Representatives members, Senate members, Supreme Court staff, Capitol Police, and congressional staff β€” was put up for sale on BreachForums by a hacker calling themselves ‘IntelBroker’. The breach was particularly significant because it exposed the personal data of a significant portion of the US legislative branch, including members of Congress and their families. The US House of Representatives Information Security Office notified all members and staff on 8 March 2023. The FBI investigated. Exposed data included names, Social Security numbers, employer-sponsored insurance plan details, and enrollment information. Speaker Kevin McCarthy and Minority Leader Hakeem Jeffries were among those whose data may have been compromised. The DC Health Benefit Exchange Authority CEO Mila Kofman testified before Congress about the breach. A second, unrelated individual (a contractor) was also charged with attempting to sell stolen DC Health Link data. The breach occurred approximately two months after a similar breach at the US Marshals Service. The exposure of legislators’ personal data, including Social Security numbers, created significant counterintelligence concerns.

Technical Details

Initial Attack Vector
Ransomware group (IntelBroker, via BreachForums) exploited a vulnerability in the DC Health Benefit Exchange Authority's (DC HBX) health insurance enrollment system to access and exfiltrate personal data for approximately 56,000 individuals including US lawmakers, their families, and congressional staff
Vendor / Product
DC Health Benefit Exchange Authority enrollment system

Timeline

  1. 2023-03-08 Breach occurred
  2. 2023-03-23 Publicly disclosed
  3. 2023-03-23 Customers notified