404 Media reported on Wednesday that a sophisticated spam operation has compromised several high-profile websites, including the U.S. Department of Health and Human Services (HHS) vaccine site. The operation includes not just the HHS website but major domains controlled by NPR, Nvidia and Stanford University. Queries for these sites now redirect real users to a spam page hosted somewhere on wowlazy.com. Unfortunately, that page is loaded with junk AI generated content and touted as an “SEO spam page.”
The specific URL of the defaced state vaccine website is es.vaccines.gov. This dastardly act is an uncommon violation. Today, the hijacked site is just running junk content created in order to drive traffic and game search engine rankings. That page on their spam site is 100% AI content farm. This should get us worried about the direction that these operations are taking and how they’re misleading users.
U.S. government websites have been hijacked on quite a few occasions in recent years. Examples of these previous violations have been used to set up fraudulent ads and even offer hacking services. The systemic vulnerabilities found on these websites speak to underlying issues with cybersecurity facing today’s public and private institutions.
Legitimate entities such as NPR, Nvidia, and Stanford University are running this spam funnel. This emphasizes both the attack’s broad scope and sophistication. Each of these institutions has a marvelous online presence. Yet, that visibility makes them attractive targets for actors who want to capitalize on their trustworthiness through deception.
Now, with the investigation into this enormous spam operation still ongoing, experts are calling for website administrators to step up their security measures. Rarely do the headlines explain that AI is being used to generate content for spammy pages. This tactic has grown much harder to identify and push back against over the years.
To view the original content of the vaccine website before its defacement, you can view an archived version of it here. It’s as easy as clicking right here!