DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Hackers Obtain Names, Social Security Numbers For 78K In Maryland

Posted on July 6, 2019 by Dissent

Deb Belt reports:

The names and Social Security numbers of 78,000 Marylanders were accessed by hackers who breached Maryland Department of Labor databases, state officials said July 5. While customers whose personal information was accessed are just now being notified, the breach happened in April and involved data files from 2009, 2010, 2013 and 2014.

State investigators have found no evidence that the personal information was downloaded. The files breached were stored on the Literacy Works Information System and an old unemployment insurance service database, according to a news release.

Read more on Patch.  The state issued the following statement yesterday:

Department of Labor Details Response to Cybersecurity Incident

Thorough Investigation Has Found No Information Misused;
Affected Customers Offered Free Credit Monitorings

BALTIMORE (July 5, 2019) – The Maryland Department of Labor today began notifying 78,000 customers with details about potential unauthorized activity on two of its database systems. While some personally identifiable information may have been accessed without authorization, a thorough investigation conducted by the Department has not revealed any misuse of the accessed data.

Earlier this year, at the request of the Maryland Department of Labor, the Maryland Department of Information Technology—the agency overseeing all state information technology functions and policies—initiated an investigation and determined that files stored on the Literacy Works Information System and a legacy unemployment insurance service database were subject to possible unauthorized access through the Internet.

Upon notification of the possibility of unauthorized access, Maryland DoIT implemented countermeasures and initiated an investigation. Working with the Department of Labor, Maryland DoIT also notified law enforcement and retained an independent expert to investigate how the information was accessed. A full review of the department’s protocols and security measures has been completed to prevent future incidents. To date, this investigation has not produced evidence to confirm that any personally identifiable information was downloaded or extracted from Labor servers.

With this investigation now complete, the Department of Labor is contacting the customers who were impacted by the incident and encouraging them to carefully monitor their accounts. Those who have been affected will be offered two years of free credit monitoring through an independent service.

Customers who believe they have been affected by the incident can contact the Department of Labor’s dedicated hotline by e-mailing [email protected] or calling 410-767-5899. This hotline will be staffed Monday-Friday from 8:00 a.m. – 4:30 p.m. For additional information, please visit the Maryland Department of Labor data hotline web page.

Files stored on the Literacy Works Information System (LWIS) and a legacy unemployment insurance service database were subject to the incident. The LWIS files impacted were from 2009, 2010, and 2014. These files possibly contained first names, last names, social security numbers, dates of birth, city or county of residence, graduation dates and record numbers. The files impacted on the unemployment insurance service database were from 2013 and possibly contained first names, last names, and social security numbers.

“We live in an age of highly sophisticated information security threats,” said Acting Labor Secretary James E. Rzepkowski. “We are committed to doing all we can to protect our customers and their information. We strongly urge those impacted to be vigilant about unusual activity on their accounts, and to take advantage of the credit monitoring being offered by the state.”

The increasing volume and enhanced capabilities of malicious actors have highlighted the importance of further securing data. Recognizing this growing threat, Governor Larry Hogan issued an executive order in June, which included hiring a Maryland Chief Information Security Officer and establishing the Office of Security Management and the Maryland Cybersecurity Coordinating Council. The three entities will work together to strengthen the state’s cybersecurity infrastructure while solidifying its ability to manage and minimize the consequences of a cybersecurity incident.

“Maryland is working to ensure its cybersecurity strategy and policy are in alignment with best practices and the latest federal standards and guidelines,” said John Evans, Maryland’s Chief Information Security Officer. “We are working with the Department of Labor to minimize the impact of this breach, and to prevent future misuse of state systems.”

For more information on protecting yourself from identity theft, including information on how to place freezes on your credit accounts, visit the Maryland Attorney General’s Identity Theft Unit online.

About the Maryland Department of Labor
The Maryland Department of Labor is committed to safeguarding and protecting Marylanders. We’re proud to support the economic stability of the state by providing businesses, the workforce, and the consuming public with high-quality, customer-focused regulatory, employment, and training services. For updates and information, follow the Maryland Department of Labor on Twitter (@MD_Labor), Facebook and visit our website.


Related:

  • PowerSchool commits to strengthened breach measures following engagement with the Privacy Commissioner of Canada
  • Two more entities have folded after ransomware attacks
  • Global hack on Microsoft product hits U.S., state agencies, researchers say
  • Inquiry launched after identities of SAS soldiers leaked in fresh data breach
  • Michigan ‘ATM jackpotting’: Florida men allegedly forced machines to dispense $107K
  • Premier Health Partners issues a press release about a breach two years ago. Why was this needed now?
Category: Government SectorHackU.S.

Post navigation

← UK: Eurofins Scientific: Forensic services firm paid ransom after cyber-attack
Croatian government targeted by mysterious hackers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot
  • AIIMS ORBO Portal Vulnerability Exposing Sensitive Organ Donor Data Discovered by Researcher
  • Two Data Breaches in Three Years: McKenzie Health
  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack
  • The safe place for women to talk wasn’t so safe: hackers leak 13,000 user photos and IDs from the Tea app

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Congress tries to outlaw AI that jacks up prices based on what it knows about you
  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard
  • Trump Administration Issues AI Action Plan and Series of AI Executive Orders
  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.