As citizens adjust their daily lives to reduce the chances of catching or spreading COVID-19, the risks associated with the pandemic are extending beyond a national health and economic crisis. Cyberthreats, including phishing scams, spam, and other attacks against organizations are spiking by as much as 40% as bad actors seek to take advantage of global uncertainty and anxiety, according to new data from CNBC.
Cyber concerns are running particularly high in the public sector. Government agencies, not used to the concept of a remote workforce, are suddenly confronted with the task of reducing the cyber risk associated with hundreds and thousands of potentially insecure home offices. Meanwhile, these already over-taxed resources must continue to ensure the ongoing security of their traditional IT infrastructures.
The government finds itself in a vulnerable place
It’s a new world order that is playing out at both the state and local and federal levels.
Meanwhile, the federal government agencies that citizens depend on for facts and information during this crisis are under attack.
In mid-March, the U.S. Department of Health and Human Services (HHS) suffered a cyberattack designed to undermine the government’s response to the COVID-19 pandemic, reports Bloomberg. The attack, likely by a foreign actor, overloaded HHS servers with millions of hits over several hours, with the goal of slowing agency systems. In an interesting twist, officials also believe that the attack is linked to a series of fake messages spread by text, email, and social media falsely claiming that President Trump would soon order a two-week mandatory quarantine for the nation.
Agencies must step up their cyber vigilance
During these dark times, it’s critical that government agencies step up their cyber vigilance. All it takes is a misconfigured piece of software or an insecure home Wi-Fi network for a hacker to gain entry to critical systems, take them offline, breach data, or spread disinformation. It’s a risk agencies can’t afford to take.
Yet no matter how much money agencies spend to protect their systems and data, they are frequently outwitted, outcomes aren’t improving, and opportunistic attacks are on the rise.