Dive Brief:
- The District of Columbia Housing Authority suffered a cybersecurity incident June 28, a disruption that led to a shutdown of its network systems and impacted the public housing authority for weeks.
- DCHA announced July 17 that a “limited subset” of data was compromised in the attack, including sensitive information. It was able to resume normal operations for all departments July 20 and said it will continue to provide updates as experts conduct a forensic investigation.
- DCHA services approximately 30,000 families and said it is providing credit monitoring and identity theft assistance.
Dive Insight:
Cyberattacks on public agencies are on the rise, partly due to AI. A recent survey found state CIOs are losing confidence in their ability to combat them.
The disruptions from such attacks can be long-lasting. St. Paul, Minnesota, spent months climbing back from a ransomware attack last year, and most city services in Foster City, California, were frozen for weeks this past spring as it dealt with the fallout from a ransomware incident.
Public housing authorities have limited resources and deep wells of personally identifiable information of their residents — including income validation data and W2s, Troy LePage, chief operating officer and executive vice president of HAI Group, a cybersecurity insurance provider, said during a May webinar.
“I don’t really believe that the bad actors are targeting public housing authorities, I think they’re targeting opportunity,” LePage said. “I think there’s been a lot of success in that space, and with success is going to come repetition, and I would extend that out to municipalities.”
“So when you add the existence of value and also the opportunity that presents itself to the bad actors in that they’ve proven to be successful, I think it’s a bad combination, and I think that it’s important that public housing authorities realize that,” LePage added.
The attacks can come without warning, panelists on the webinar said, and bad actors can gain access by exploiting human error using tactics like email phishing. Lansing Housing Commission in Lansing, Michigan, which suffered a data breach in 2020, discovered the attackers had been in the housing authority’s system for three or four months before they attacked. “They were just hanging out there,” said Doug Fleming, LHC’s executive director.
DCHA said it follows industry standards for cybersecurity and data protection, including round-the-clock threat monitoring, multifactor authentication, layered email security and endpoint protection. The authority said it has taken additional measures to strengthen its network security in the wake of the cybersecurity incident and is upgrading its cybersecurity policies, procedures and protocols.