FDA Cybersecurity Incidents Counted
FDA reported 1,036 cybersecurity incidents between 1/2013 and 6/2015, according to a Federal Times report based on information obtained through a Freedom of Information Act request. Some 50% of the incidents were attributed to unauthorized access, while 21% were scans, probes, or attempted access, and 19% were malicious code discovered on FDA systems.
The article says that while the threat vectors track closely to what is happening at most HHS agencies, the likely reasons behind the hacks are unique to FDA.
“There has been a huge amount of hacking in the pharmaceutical world,” says DRI International president Al Berman in the article. “One of the reasons this is being done is for stock manipulation. If you can find out where somebody is in the testing phase for a drug … if you can figure out where they are in the cycle or how well it’s going, I think that’s tremendous information, with different reasons than any other hack you’ve seen.”
Information security officials at HHS agencies are very aware of the sensitivity of the data they protect, according to HHS cybersecurity official Leo Scanlon. He told Federal Times that the department uses threat data to build a profile of how agencies such as FDA are being attacked and then develop a response in kind.