CSIDB logo
Incident

Georgia Department of Human Services

Incident posture

Attack window
Jul 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:26

Linked entities

Victim
Georgia Department of Human Services
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers launched a bot-driven cyberattack against a third-party contractor's interactive voice response system used for electronic benefit transfer (EBT) account inquiries, forcing service disruptions at the call center and prompting the agency to encourage SNAP cardholders to change their PINs and lock their cards. The contractor detected an unusual spike in inbound calls and took steps to block suspicious activity, though officials did not confirm whether account information was successfully obtained. The incident is part of a broader pattern of EBT and SNAP fraud linked to international crime rings, with criminals reportedly cloning point-of-sale terminals to steal benefits and taxpayer funds.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 1, 2025, the Georgia Department of Human Services (DHS) confirmed that a cyberattack had targeted the state's privately contracted call center for the Supplemental Nutrition Assistance Program (SNAP), commonly known as food stamps. The attack occurred on Monday, July 28, 2025, and was aimed at Conduent, the third-party vendor that manages electronic benefit transfer (EBT) account services for Georgia. According to DHS, bots were used to bombard Conduent's interactive voice response (IVR) system, which cardholders use to call in and obtain account details such as their current benefit balance. The cyberattack forced a disruption in service and represented an attempt to improperly access EBT accounts belonging to Georgia SNAP recipients.

Conduent, the contractor responsible for operating the call center as well as the ConnectEBT app, did not officially confirm that a cyberattack had taken place when contacted by Atlanta News First Investigates. Instead, the company stated that its system had "detected an unusual spike in inbound calls." Conduent further noted that such attempts are often experienced in a call center environment and that, at the request of the state of Georgia, the company took steps to block suspicious activity. The company indicated it would continue to monitor the situation closely but declined to answer additional questions about the incident or its security measures.

DHS did not confirm whether the hackers successfully obtained any account information during the attack. The call center was taken offline over the weekend following the incident as the investigation continued, and it experienced another outage on the Tuesday morning following the initial attack. In response, Georgia officials urged SNAP cardholders across the state to change their PINs as a protective measure and to lock their EBT cards using the ConnectEBT website or mobile app, a security feature launched the previous year that allows users to lock and unlock their cards between purchases. Cardholders were also directed to use the ConnectEBT platform to monitor their accounts for any signs of unauthorized activity.

The attack on Georgia's SNAP call center occurred against the backdrop of a broader and ongoing wave of EBT fraud affecting recipients nationwide. According to data referenced in reporting, criminals stole approximately $350 million in taxpayer dollars through SNAP-related fraud in the previous year alone. The U.S. Department of Agriculture reported a drastic increase in EBT fraud during the final quarter of 2024, with incidents rising by 350 percent compared to the first quarter of that year. Much of this fraud has been linked by federal investigators, including the U.S. Secret Service, to international crime rings that employ sophisticated techniques such as cloning point-of-sale terminals to skim benefit information directly from retailers' payment systems. In many cases reported by Atlanta News First Investigates, victims in Georgia and several other states have had their entire monthly food benefits drained from their cards shortly after funds were added, sometimes across multiple states within a span of less than two minutes.

In light of these broader fraud patterns, Conduent had announced enhancements to its EBT fraud prevention efforts in a July 22 press release, prior to the Georgia incident. These enhancements included the deployment of "intelligent voice systems that detect suspicious calls," indicating that the contractor had been actively working to improve its ability to identify and respond to threats targeting its call center infrastructure. Despite these measures, the recent attack demonstrated that automated bot-based attacks against the IVR system remained a viable threat vector for attempting to gain unauthorized access to EBT account information.

Sources

Sources available to members: 1 source.

CSIDB