Anthem Inc. disclosed on the evening of Feb. 4, 2015, that attackers had taken records on what it first described as about 80 million people and later fixed at 78.8 million. The data included names, Social Security numbers, birth dates, addresses, phone numbers, email addresses, member identification numbers and employment and income information. At least 12 million of the records belonged to minors, according to California’s insurance regulator. No clinical data or card numbers were taken, the company said.
The intrusion had been running for most of a year. A spearphishing email was sent to an Anthem subsidiary on Feb. 18, 2014. A backdoor gave the attackers access from May 13, 2014. They spent October and November mapping the enterprise data warehouse and ran the queries that extracted it in December 2014 and January 2015. Anthem found them in the last days of January.
What An Insurer’s Warehouse Holds
The target was the data warehouse, the system built so that the whole membership can be analysed in one place. It is where an insurer’s identity data is most complete and most convenient, and the attackers moved through at least 90 systems to reach it. What left was the identity profile of a quarter of the U.S. population, held by a company most of them had never chosen, because their employer had.
The Indictment, And What It Did Not Say
On May 9, 2019, the Justice Department unsealed an indictment in the Southern District of Indiana charging Fujie Wang and a second, unnamed defendant as members of a hacking group operating in China. The charges were conspiracy, wire fraud and intentional damage to protected computers. The indictment does not allege that the group worked for the Chinese state. A California Department of Insurance report of January 2017 had concluded with medium confidence that the attacker acted on behalf of a foreign government. The two are different claims, and the file carries both with their sources.
The same actors were linked, by the same researchers, to the Premera and CareFirst intrusions filed at 15-0317 and 15-0520. The lookalike domain we11point[.]com, registered in April 2014, was part of the infrastructure. Nobody was ever arrested.
What It Cost, And Who Received It
The class action settled for $115 million with final approval in August 2018, the largest data-breach settlement at the time. The Department of Health and Human Services settled for $16 million on Oct. 15, 2018, then the largest health-privacy penalty ever, after finding no enterprise-wide risk analysis, insufficient activity review and inadequate access controls. Forty-four attorneys general settled for $39.5 million on Sept. 30, 2020, and California separately for $8.69 million. Anthem told regulators it had spent more than $260 million on the response.
A decade later the breach is the sector’s reference point, and the file records why in one number. The Social Security numbers of 78.8 million people do not expire, and the monitoring the settlement paid for ran out years ago.
Compiled from the Justice Department indictment, the HHS resolution agreement, the multistate settlement announcement and contemporaneous reporting, listed below. Dates in the attack timeline are the indictment’s. The state-sponsorship assessment is a state regulator’s and is distinguished from the criminal charges. Graded high. Corrections: corrections@forensicpost.com.
- Member of Sophisticated China-Based Hacking Group Indicted for Series of Computer IntrusionsU.S. Department of Justice
- Anthem, Inc. resolution agreementU.S. Department of Health and Human Services
- Attorney General Josh Stein Reaches $39.5 Million Multistate Data Breach Settlement with AnthemNorth Carolina Department of Justice
- Foreign Nation Behind Anthem Breach, Investigation ClaimsSecurityWeek
- Health insurer Anthem hit by hackersCBS News