{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million"},"incident":{"slug":"2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million","title":"Premera Blue Cross breach began with a spear-phishing email, 10.4 million affected","date":"2014-05","date_precision":"month","year":2014,"victim_org":"Premera Blue Cross","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Espionage"],"loss_usd":6850000,"loss_kind":"business_impact","loss_note":"US$6.85 million HIPAA penalty imposed by HHS Office for Civil Rights in 2020; separate class-action and multistate settlements followed.","records_affected":10400000,"threat_actor":null,"summary":"Attackers compromised Premera Blue Cross in May 2014 and remained undetected for about nine months until January 2015. The intrusion exposed the protected health information of roughly 10.4 million individuals, including names, dates of birth, Social Security numbers, bank account details and clinical information. The HHS Office for Civil Rights, describing the incident, stated that the entry point was a spear-phishing email that installed malware.","how_it_worked":"The intrusion started with a spear-phishing email sent to Premera staff which, when acted on, installed malware and gave the attackers an interactive foothold inside the health plan's network. From there they operated quietly for nine months, moving through systems that held member enrolment, claims and clinical data. The regulator's later findings emphasised that Premera had not run an adequate enterprise-wide risk analysis and lacked the monitoring that would have surfaced anomalous internal activity, which is why a single successful email turned into nine months of undetected access across a database of more than ten million members.","lessons":"Email filtering and user reporting only reduce the odds; the decisive control here was internal detection, since the damage came from nine months of unnoticed lateral movement.","confidence":"Confirmed","sources":[{"title":"OCR Imposes 2nd Largest Ever HIPAA Penalty of $6.85 Million on Premera Blue Cross","url":"https://www.hipaajournal.com/ocr-imposes-2nd-largest-ever-hipaa-penalty-of-6-85-million-on-premera-blue-cross/","publisher":"HIPAA Journal"},{"title":"Premera Blue Cross Breach Exposes Financial, Medical Records","url":"https://krebsonsecurity.com/2015/03/premera-blue-cross-breach-exposes-financial-medical-records/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million"}}