The FBI is investigating a data breach affecting members and staff of the U.S. House of Representatives. The breach occurred after accounts and sensitive personal information were stolen from DC Health Link servers .

DC Health Link is the organization that manages the health care of members of the House of Representatives, staff, and their families.
People affected by the data breach were notified via email by Catherine L. Szpindor, the head of administration for the U.S. House of Representatives.
See also: Northern Essex Community College hit by cyberattack
“DC Health Link suffered a significant data breach, potentially exposing the Personally Identifiable Information (PII) of thousands of enrollees. As a member or employee eligible for health insurance through DC Health Link, your data may have been included,” Szpindor said. “At this time, I do not know the size and scope of the breach, but I have been advised by the Federal Bureau of Investigation (FBI) that account information and PII of hundreds of employees and members of the House were stolen… It is important to note that at this time, it does not appear that members or the House of Representatives were the specific target of the attack.”
Stolen data is sold online
Szpindor did not provide further details about the data that was stolen, but according to BleepingComputer, there is at least one threat (IntelBroker) selling the information of members of the US House of Representatives on a hacking forum.
See also: Microsoft Excel: Blocks untrusted XLL add-ins by default
According to the forum post, the data breach affects approximately 170,000 people and the stolen data includes names, dates of birth, addresses, phone numbers, email, social security numbers, and more.
The data has been up for sale since Monday, March 6. The seller, IntelBroker, claims it was stolen after a breach of the DC.gov Health Benefit Exchange Authority. Interested parties will have to pay in Monero crypto. However, a specific price has not been given for the stolen data.

In fact, the seller claims that there has already been at least one buyer.
The ad was removed from the forum on Wednesday evening.
The seller had been on the forum for months and was selling compromised databases ,according to CNN.
"Like other financially motivated actors, (this actor) is opportunistic rather than seeking to target specific regions or sectors," a senior researcher told CNN.
See also: Emotet malware is back after a three-month “hiatus”
In a statement to BleepingComputer, Adam Hudson, the Public Information Officer for the Health Benefit Exchange Authority, confirmed that some of the stolen data was exposed online:
“We can confirm reports that data from some DC Health Link customers has been exposed in a public forum. We have launched a comprehensive investigation and are working with experts and law enforcement. At the same time, we are taking action to ensure the security and privacy of our users’ personal information. We are in the process of notifying affected customers and will be providing identity and credit monitoring services. In addition, and out of an abundance of caution, we will also be providing credit monitoring services for all of our customers. The investigation is ongoing and we will provide more information when we have more to share.“.

Data breaches are serious events that can have devastating consequences. As such, it is important for companies and organizations to understand what data breaches are and how they work so that they can take steps to prevent them from happening in the first place. This means investing in strong security measures, such as encryption software and regular penetration testing, as well as training employees on proper security protocols so that they don’t inadvertently give away sensitive information without realizing it. Taking these steps will significantly reduce the chances of your company falling victim to a data breach.
Source: www.bleepingcomputer.com
