{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai"},"incident":{"title":"Anthem breach of 78.8 million records started with a spear phishing email","date":"2015-02-04","date_precision":"day","victim_org":"Anthem Inc.","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Espionage","Identity Theft"],"loss_usd":115000000,"loss_note":"Anthem agreed to a $115 million class-action settlement in 2017 and a $16 million HIPAA settlement with HHS OCR in 2018, plus a multistate settlement of about $39.5 million in 2020; the figure given is the class-action settlement only.","records_affected":78800000,"threat_actor":"China-linked espionage group (reported as Deep Panda / Black Vine; US DOJ later indicted Fujie Wang and others)","summary":"Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.","how_it_worked":"A targeted email delivered to at least one subsidiary employee installed a backdoor on the workstation. The attackers used that access to move laterally, harvest credentials and eventually obtain the credentials of database administrators, allowing them to query Anthem's data warehouse directly. Data was staged and exfiltrated over months to external infrastructure, including domains that typosquatted the company's former name. The activity was noticed only when an administrator saw a database query running under his own account that he had not issued.","lessons":"Privileged database accounts should require phishing-resistant MFA and behavioural monitoring, and bulk queries against member data warehouses should alert regardless of which account issues them.","confidence":"Confirmed","sources":[{"title":"Commissioner Jones Announces Examination Findings of Anthem Cyber Attack","url":"https://www.insurance.ca.gov/0400-news/0100-press-releases/anthemcyberattack.cfm","publisher":"California Department of Insurance"},{"title":"Anthem Data Breach: What Happened, Impact, and Lessons","url":"https://www.huntress.com/threat-library/data-breach/anthem-data-breach","publisher":"Huntress"},{"title":"The Anthem Hack: All Roads Lead to China","url":"https://threatconnect.com/blog/the-anthem-hack-all-roads-lead-to-china/","publisher":"ThreatConnect"}],"entry_type":"incident","slug":"2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai","year":2015,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai"}}