In a statement to The Hill, the department said although no “HHS systems or networks were compromised, attackers gained access to data by exploiting the vulnerability in the MOVEit Transfer software of third party vendors.”
“HHS is taking all appropriate actions … and will provide Congress with additional information as the investigation continues,” an HHS official said.
HHS is the latest agency that was reportedly affected by the breach. It was also reported that the Department of Energy was also impacted and asked to pay a ransom.
The Russian-speaking ransomware group known as CLoP is reportedly behind the government hack.
The hackers exploited a vulnerability in a software application known as MOVEit, which is widely used by government agencies to transfer files.
Read more in a full report at TheHill.com.