HealthCare.gov, the nation’s health insurance enrollment website, was breached in July. Attackers uploaded malware to a test server and used default credentials to gain access to the server. The malware was designed to add the server to a botnet and launch a Denial of Service attacks against other websites, or deliver spam when activated. No personal information was compromised, according to the Health and Human Services Department. The breach was discovered on August 25 by a CMS security team after an anomaly was detected in the security logs of one of the servers.”]
Source: https://www.csoonline.com/article/2602964/configuration-errors-lead-to-healthcare-gov-breach.html