What happened
Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.
How the deception worked
A targeted email delivered to at least one subsidiary employee installed a backdoor on the workstation. The attackers used that access to move laterally, harvest credentials and eventually obtain the credentials of database administrators, allowing them to query Anthem's data warehouse directly. Data was staged and exfiltrated over months to external infrastructure, including domains that typosquatted the company's former name. The activity was noticed only when an administrator saw a database query running under his own account that he had not issued.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Privileged database accounts should require phishing-resistant MFA and behavioural monitoring, and bulk queries against member data warehouses should alert regardless of which account issues them.
Sources (3)
- Commissioner Jones Announces Examination Findings of Anthem Cyber AttackCalifornia Department of Insurance·insurance.ca.govOpen ↗
- Anthem Data Breach: What Happened, Impact, and LessonsHuntress·huntress.comOpen ↗
- The Anthem Hack: All Roads Lead to ChinaThreatConnect·threatconnect.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.