Desk live·
ForensicPost
Insurance/Health/File 15-0909

Excellus Attackers Had 17 Months Inside Before Anyone Looked, Reaching 10.5 Million

The Rochester insurer’s intrusion began by Dec. 23, 2013, and was found on Aug. 5, 2015, by a forensic review ordered after the other Blue Cross breaches. Social Security numbers, bank details and clinical information were in scope. Federal regulators later put the price at $5.1 million.

Constructed geometry · not a chart of case data
JurisdictionUSARochesterthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetExcellus BlueCross BlueShield
ActorUnattributed
D. Kennedy10 min readConfidence: high4 sources reviewed

Excellus BlueCross BlueShield announced on Sept. 9, 2015, that attackers had been inside its systems since at least Dec. 23, 2013. The company put the affected population at about 10.5 million people across Excellus and its Lifetime Healthcare affiliates. Federal regulators later used a figure of more than 9.3 million. Exposed fields included names, addresses, birth dates, Social Security numbers, bank account information, health plan claims and clinical treatment records.

The intrusion was found on Aug. 5, 2015, by Mandiant, which Excellus had hired to review its environment after the Anthem, Premera and CareFirst disclosures earlier that year. Access had continued until May 11, 2015, according to the Department of Health and Human Services.

The Longest Of The Four

Among the four Blue Cross breaches disclosed in 2015, Excellus had the longest dwell and the widest field list. Anthem, filed at 15-0204, lost identity data on 78.8 million. Excellus lost identity, financial and clinical data on a tenth as many, and the attackers held access for roughly 17 months. Regulators found that the company had never conducted an enterprise-wide risk analysis and had failed at information system activity review, the control that reads logs for exactly this kind of presence.

The Federal Settlement

On Jan. 15, 2021, HHS announced a $5.1 million settlement with Excellus and a corrective action plan. The agency cited failures in risk analysis, risk management, activity review and access controls. No attribution was made by the company or the government, and the entry vector was never published.

A Class Action That Paid No Member

Fero v. Excellus Health Plan was filed in the Western District of New York within weeks of the announcement. The court certified a class for injunctive relief only. The settlement approved on April 29, 2022, bound Excellus to security commitments the parties valued at $10.66 million and paid $3,554,500 to class counsel. Members received no cash.

The outcome is typical of the era and worth recording plainly: seven years after a breach that exposed Social Security numbers and diagnoses on 10 million people, the affected received a promise about future controls, the lawyers received a fee, and the regulator received $5.1 million.

How we reported this

Compiled from the HHS resolution announcement, Excellus’s disclosures as reported and the court record in Fero v. Excellus, listed below. The 10.5 million figure is the company’s; 9.3 million is the regulator’s. Both are stated with their source. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Health Insurer Pays $5.1 Million to Settle Data BreachHHS
  2. Settlement Reached in Excellus Class Action Data Breach LawsuitHIPAA Journal
  3. Excellus to pay $5 million to settle charges stemming from breach that impacted 9.3 millionDatabreaches.net
  4. Fero v. Excellus Health Plan, Inc., No. 6:15-cv-06569 (W.D.N.Y.)Justia
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary