Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Anthem Data Breach – Why Have Nation-State Hackers Targeted a Health Insurer, And What Can We Do About it?
News & Analysis

Anthem Data Breach – Why Have Nation-State Hackers Targeted a Health Insurer, And What Can We Do About it?

ISBuzz TeamBy ISBuzz TeamFebruary 13, 2015Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
anthem
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

U.S. health insurance giant Anthem confirmed last week that data on as many as 80 million customers at was stolen by hackers. The stolen information includes names, birth dates, social security numbers, street addresses, email addresses, and employment information, the company said. It is very likely that this attack has been going on for months, and there is strong evidence suggesting links to ongoing Chinese hacking campaigns.

The sophisticated attackers gained unauthorized access to one of Anthem’s IT systems (presumably using a stolen employee password) and have obtained personal information relating to consumers and Anthem employees who are currently covered, or who have received coverage in the past, by the company.

Free Cyber Security Training! Join the revolution today!

This seems like a disturbing change in the familiar ways of Chinese cyber espionage. We’ve come to expect that Chinese spies will infiltrate the defense industry, auto makers, and government networks for the purposes of data exfiltration or cyber espionage.

But a health insurer seems like an unusual target for these state of the art hackers. Why would a military unit or state-backed hacker bother with such an unexciting target? Surely they are not after the money. (Although it is known that medical and personal records yield a far greater profit on the underground markets than credit card data, making them very lucrative target for financial hackers) There are several possible reasons for this.

Some say that this was simply an exercise of sorts to train novice Chinese cyber troops, and as such a rather “soft” target was selected. Another, more intriguing explanation is that they were looking for something or someone in particular – among those millions of customers must lay some high ranking officials (or their family members), and this information could be used for elaborate social engineering attacks which could succeed in the entrapment of a senior executive, providing access to very sensitive information. Then again, it could be that China simply hacks anything and everything American, and since they’ve pretty much breached and drained a number of existing major industries (defense, aerospace, automotive, academia, etc.), they are now moving to secondary targets, which provides them access not only to secret government information and lucrative technology but also to the homes and bank accounts of average Joes.

Whatever the rationale for this breach, it is frightening to think that corporates, who until now only dealt with cybercrime, must now somehow mitigate this new threat actor with seemingly endless resources and motivation.

But when the actual breach is analyzed, it shows a rather simple (yet proven) attack method, and to a certain degree, the end result might be blamed on the victim’s lack of preparedness and not on the superb skill set and tools of the attackers. From what is known, it appears that this breach, like so many before it, occurred using the stolen credentials of an employee – most likely with privilege access rights, like an administrator (some information indicates that credentials of 5 employees were utilized). Once they gained access to the network, the attackers took their time (some say the attacked started at December 2014, others say it started back in April) to locate the customer records which weren’t encrypted. They then managed to siphon at least some of these records outside the organization until the breach was detected. Utilizing privilege access rights, the attackers bypassed most security controls and succeeded in their mission.

While the full extent of the damage is not yet clear, (Anthem’s stock took a hit the day after the breach but recovered shortly thereafter, and the costs of recovery are not yet known.) it is certain that the company’s reputation and credibility will suffer. It is also likely that the company’s management will pay the price for this breach, as was the case with Target and Sony breaches.

To read about some of the lessons we glean from this breach, please view the original article on Cytegic’s blog here.

About Cytegic

cytegicCy-te-gic /pronounced: sʌɪ-ˈtē-jik/ adjective: A plan of action or strategy designed to achieve a long-term and overall successful Cyber Security Posture Optimization – “That firm made a wise Cytegic decision”.

Cytegic develops a full suite of cyber management and decision-support products that enable to monitor, measure and manage organizational cyber-security resources.

Cytegic helps organization to identify threat trends, assess organizational readiness, and optimize resource allocation to mitigate risk for business assets.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}