Skip to main content

Protecting the 988 Crisis Lifeline from Cyberattacks that Could Disrupt Lifesaving Support

Posted on September 24, 2026

Each year, the 988 Suicide and Crisis Lifeline, a national suicide prevention helpline, gets millions of calls, texts, and chats from people in crisis. 

When people face hard times, the crisis line can provide lifesaving support. But a cyberattack could threaten this important resource.  

Today’s WatchBlog post looks at our report on these risks and what could be done to better secure this important crisis resource.

Image

A phone where the 988 crisis line is being called.

What’s at risk if the 988 Lifeline is attacked?

In short, the stakes are high.  

A few years ago, the 988 Lifeline experienced a ransomware attack that resulted in a nationwide service disruption lasting several hours. The outage raised concern about its 24/7 availability and security of its IT systems. The incident also exposed a significant vulnerability in the crisis line’s operations.  

Lives could be at risk. In January alone, the 988 Lifeline handled 428,000 calls from people in suicidal crisis or emotional distress.  

Should it fall victim to another cyberattack, a disruption of services could mean calls for help go unanswered. It could also prevent people in crisis from accessing critical support when they need it.  

Personal information may be exposed. When people call the crisis line for help, they may share some personal information and data. A cyberattack could expose such sensitive mental health information and other personally identifiable information. For example, while a contact’s name is not expressly recorded by crisis contact centers, it may be documented in a voice, chat, or text log if volunteered during a counseling session.  

Having strong cybersecurity practices in place is critical. But we found that important safeguards are not always followed. For example, we found that the 988 Lifeline’s network administrator used outdated password practices that weakened account security and could increase the risk of unauthorized access to sensitive information.  

So, what’s being done to protect this lifesaving resource? 

One of the challenges in securing the 988 Lifeline is its scale. The crisis line operates nearly 220 crisis contact centers, which are staffed by trained counselors who provide free and confidential 24/7 support.  

The Department of Health and Human Services (HHS) and the network administrator oversee the 988 Lifeline. And they work with other federal, state, local, and private-sector partners to fund and operate it. 

But our report found some gaps in HHS’s oversight. For example, HHS didn’t include certain cybersecurity protections in its agreements governing the 988 Lifeline. These protections included having stronger email security and requiring staff to use separate accounts when accessing sensitive parts of a system. This helps limit the damage if an account is compromised.  

And while the department has defined roles and responsibilities for itself and network administrators on monitoring cybersecurity, we found it didn’t always follow its established processes. As a result, cybersecurity measures may vary across the network. 

In addition, having more safeguards in place could better prevent unauthorized access in the future. This includes safeguards such as updated password guidance and incident response plans. 

Without fully implementing cybersecurity controls or safeguards, the 988 Lifeline faces increased risk of attacks. This could result in prolonged service disruptions and unauthorized access to private mental health information. And it could potentially prevent people in crisis from accessing mental health support when it’s needed. 

Learn more about this issue and our recommendations for addressing it by reading our full report.  


  • GAO’s fact-based, nonpartisan information helps Congress and federal agencies improve government. The WatchBlog lets us contextualize GAO’s work a little more for the public. Check out more of our posts at GAO.gov/blog.  
  • Got a comment, question? Email us at blog@gao.gov.   

GAO Contacts

Related Products

About Watchblog

GAO's mission is to provide Congress with fact-based, nonpartisan information that can help improve federal government performance and ensure accountability for the benefit of the American people. GAO launched its WatchBlog in January, 2014, as part of its continuing effort to reach its audiences—Congress and the American people—where they are currently looking for information.

The blog format allows GAO to provide a little more context about its work than it can offer on its other social media platforms. Posts will tie GAO work to current events and the news; show how GAO’s work is affecting agencies or legislation; highlight reports, testimonies, and issue areas where GAO does work; and provide information about GAO itself, among other things.

Please send any feedback on GAO's WatchBlog to blog@gao.gov.