CSIDB logo
Incident

Kentucky Office of Unemployment Insurance

Incident posture

Attack window
Feb 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
Kentucky Office of Unemployment Insurance
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Kentucky's unemployment insurance claims system experienced a possible cyberattack involving random login attempts aimed at overwhelming the external website, though no security breach or compromise of claimant information occurred. The state's Office of Homeland Security collaborated with relevant agencies to address the incident, which temporarily prevented external access to the claims portal while internal staff continued assisting users. The disruption appeared consistent with attempts to disrupt service availability rather than infiltrate data systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 24, 2021, the Kentucky Career Center reported a potential cyberattack targeting the state’s external unemployment insurance claims system. The Office of Unemployment Insurance (OUI) detected anomalous activity at approximately 10:40 a.m. and alerted Labor Cabinet leadership. Initial assessments indicated no confirmed security breach or compromise of claimant data. Attackers employed random login credentials in an attempt to overwhelm the website’s infrastructure, a tactic consistent with a distributed denial-of-service (DDoS) attack. None of the fraudulent login attempts succeeded in gaining unauthorized access to the system. The incident occurred amid broader national reports of unemployment fraud during the COVID-19 pandemic, though officials did not explicitly link this event to wider criminal campaigns. While external claimants lost access to the online portal during the disruption, OUI staff maintained internal operations and continued processing claims manually.

Kentucky’s Office of Homeland Security coordinated the response alongside the Labor Cabinet, OUI, and the Commonwealth Office of Technology. Technical teams worked to mitigate the attack and restore system availability, though no specific remediation timeline was publicly disclosed. Officials emphasized the absence of evidence suggesting data exfiltration or unauthorized access to sensitive claimant information. The incident temporarily hindered claimants’ ability to file or check claims online but did not halt overall unemployment assistance operations. Ongoing investigations focused on identifying the attack’s origin and scope while maintaining service continuity through alternative channels.

Sources

Sources available to members: 1 source.

CSIDB