CSIDB logo
Incident

Maryland Department of Human Services

Incident posture

Attack window
Dec 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-25 00:00

Linked entities

Victim
Maryland Department of Human Services
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack disrupted operations at the Maryland Department of Health, forcing the agency to take certain systems offline as a precautionary measure. The Maryland Security Operations Center initiated an investigation into the network security incident, though the full scope of the intrusion remained under assessment. Service interruptions persisted for multiple days, significantly impacting departmental functions during the outage period.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

A cyberattack targeting the Maryland Department of Health disrupted operations during the weekend of December 4-5, 2021, prompting officials to take systems offline. The Maryland Security Operations Center initiated an investigation into the network security incident, with department spokesman Andy Owen confirming the intrusion in a public statement. The health department implemented precautionary measures, including disconnecting certain systems from the network to contain potential threats. These actions occurred while investigators worked to assess the scope and severity of the breach. The disruption began over the weekend and extended through at least the morning of Monday, December 5, when reporting indicated systems remained offline. No specific details about the attack vector or compromised data were disclosed during this initial phase. The department's statement emphasized ongoing efforts to address security concerns while maintaining operational integrity.

The incident caused significant operational paralysis, described as freezing the health department's capabilities, though specific affected services weren't enumerated. Response actions focused on containment through system isolation and implementing additional unspecified security precautions. The prolonged downtime suggested substantial infrastructure impact, with recovery efforts continuing beyond the initial attack window. No ransomware claims or threat actor attribution appeared in available reporting. The Washington Post's coverage highlighted the seriousness of the disruption but noted limited public details about patient data exposure or clinical service interruptions. Maryland's centralized security team maintained investigative control while the health department operated in a reduced-capacity state during remediation.

Sources

Sources available to members: 1 source.

CSIDB