august

Anthem, 2015

The Discovery

On January 27, 2015, a database administrator at Anthem, the second-largest health insurer in the United States, noticed something wrong with his own name. A query was running against the company's enterprise data warehouse under his credentials — his account, his privileges — and he had not started it. He killed the query and alerted Anthem's information security team. Two days later the company concluded it was the victim of an attack and called the FBI; within days, forensic specialists from Mandiant were inside the network.

The investigation established that the administrator had caught the tail end of the intrusion. It had been underway for more than eleven months, and the data warehouse — the consolidated repository holding identity records on tens of millions of current and former members — had already been read, packaged, and taken. The query he happened to see was among the last steps of an exfiltration that was, for all practical purposes, complete.

Most major healthcare incidents announce themselves: ransomware displays its demand on screen, extortionists open leak sites and send emails, a clearinghouse's customers discover the outage before the clearinghouse can draft a statement. The Anthem breach caused no disruption. Nothing stopped working, no patient was turned away, no pharmacy counter froze, no ransom note appeared. The largest healthcare breach then on record was discovered because one employee recognized his own credentials running a query he had not started.

Anthem and the Scope of the Breach

Anthem in early 2015 was a company most Americans knew by other names. It had been WellPoint until a corporate renaming weeks earlier, in late 2014, and it operated Blue Cross and Blue Shield plans across fourteen states from its headquarters in Indianapolis. It insured roughly 37 million people directly — second only to UnitedHealth — and through the Blue system's reciprocal arrangements, which let a Blue member from one state receive care in another, its computers processed claims for millions of people who had never bought anything from Anthem at all.

On the evening of February 4, 2015 — about a week after detection, with the forensic work barely begun — Anthem announced the breach to the country. Chief executive Joseph Swedish called it a "very sophisticated external cyber attack" and noted that his own personal information was among the data accessed. The company initially put the exposure at up to 80 million people; the figure eventually settled at about 78.8 million records of current and former members and employees, including millions of members of other Blue Cross Blue Shield plans whose claims had simply crossed Anthem's systems. Records reached back roughly a decade. It was, at the time, the largest breach ever recorded in healthcare, a distinction it would hold until the Change Healthcare disaster described in the opening chapter.

Anthem had 37 million customers and lost 78.8 million people's records. The warehouse held more than double the company's current membership because member records were retained after coverage ended. People who had left Anthem years earlier, employees who had moved on, out-of-state patients whose only connection was a single claim routed through a Blue network — all of them were still rows in the warehouse, and all of them were taken.

The stolen fields were names, dates of birth, Social Security numbers, health plan ID numbers, street addresses, email addresses, phone numbers, and employment information including income data. Anthem said investigators found no evidence that clinical information — diagnoses, test results — or credit card numbers had been taken. That distinction mattered under breach-notification law, but the stolen fields were the core records of identity: name, address, income, employer, and Social Security number.

How the Attackers Got In

The reconstruction of the intrusion came principally from Mandiant's forensics and from a multi-year examination led by the California Department of Insurance on behalf of state insurance regulators, published in early 2017. It begins on February 18, 2014, when an employee at an Anthem subsidiary opened a spear-phishing email. The malicious attachment installed remote-access tools; from that single workstation, the attackers worked outward and upward, eventually reaching at least ninety other systems across the Anthem enterprise and culminating in the data warehouse.

Researchers later documented look-alike infrastructure registered months in advance, including the domain "we11point.com" — WellPoint with the letter L's replaced by numeral ones — created in April 2014 with subdomains mimicking the company's internal HR and VPN services, built for a sustained credential-harvesting campaign. According to the federal indictment that followed years later, the attackers ran queries against the warehouse, staged the results in encrypted archives, moved them out through a chain of intermediary computers to destinations in China, and deleted the archives to cover the exit.

The data in the warehouse was not encrypted at rest, a fact that drew extended argument after the breach. Under the HIPAA Security Rule, encryption is what the regulation calls an "addressable" specification — required where reasonable and appropriate, permissibly replaced by documented equivalent measures — and Anthem, like much of the industry, had left the warehouse unencrypted, relying on access controls instead. The company's defense was that encryption would have changed nothing, because the attackers were using a legitimate administrator's credentials, and a database must decrypt data for any authorized query. As a technical matter this was largely true: encryption at rest defeats a stolen backup tape or a lifted hard drive, but it does not defeat an adversary holding a legitimate administrator's credentials. The same defense pointed to a broader set of failures in the stewardship of privileged accounts: an administrator's credentials were phished, bulk queries ran for weeks without tripping an alarm, and gigabytes of member data left the network unnoticed. Regulators would eventually cite those failures.

Attribution and the Indictment

Attribution began circulating within days of the announcement. Investigators and threat-intelligence firms linked the tooling and infrastructure to a China-based espionage group tracked under various names — CrowdStrike's "Deep Panda," Symantec's "Black Vine" — a crew associated with the Sakula malware family and with intrusions into aerospace, energy, and technology companies going back years. The California-led insurance examination went further than private researchers usually can: the examination team announced in 2017 that it had concluded, with a medium degree of confidence, that the attacker was acting on behalf of a foreign government, a finding California's insurance commissioner, Dave Jones, characterized as reached "with a significant degree of confidence." The examination also found that Anthem's precautions before the breach, and its response once the intrusion was found, had been reasonable — a judgment few breached companies ever receive. The public disclosure, eight days after detection, drew separate notice in the trade press as unusually fast.

In May 2019 a federal grand jury in Indianapolis — Anthem's home district — returned a four-count indictment against Fujie Wang and a second defendant identified only as John Doe, charging conspiracy to commit fraud in relation to computers and identity theft, conspiracy to commit wire fraud, and two counts of intentional damage to a protected computer. The indictment described a campaign, running from February 2014 into 2015, against Anthem and three other unnamed American companies in the technology, basic materials, and communications sectors. It described the patient lateral movement, the encrypted archives, the exfiltration to China. What it did not do was name the Chinese state: the Justice Department charged two men as members of an "extremely sophisticated" hacking group operating in China and left the sponsorship question unaddressed. Wang's face went onto an FBI wanted poster. He has never been arrested.

The 78.8 million stolen records never surfaced. In the years after the breach, security firms and law enforcement watched the criminal markets where stolen identity data is bought and sold, and Anthem's data never appeared there. No wave of tax fraud or credit fraud was ever traced to the breach. Data stolen for money is monetized quickly, because it loses value as it ages; data withheld from those markets for a decade points to a buyer with no need to sell it — an intelligence service rather than a criminal ring. Investigators drew that inference cautiously in 2015, and the years since have not produced a competing explanation.

A Season of Breaches Against Health Insurers

Anthem was the loudest episode in a broader pattern of collection against American health insurers in 2014 and 2015.

The precursor came in mid-2014, when Community Health Systems, a large hospital chain, disclosed that attackers linked by investigators to a Chinese group had taken 4.5 million patients' identity records, reportedly by exploiting the Heartbleed vulnerability in a network appliance. In the weeks after Anthem's announcement, more insurers came forward. Premera Blue Cross disclosed in March 2015 that intruders had been inside its network since May 2014, exposing about 11 million people, and that it had discovered the intrusion on January 29, 2015 — the same week as Anthem's discovery, once investigators knew what to look for. Researchers found a spoofed domain, "prennera.com," registered by the same infrastructure cluster that had staged "we11point.com." CareFirst BlueCross BlueShield disclosed 1.1 million records that May. Excellus BlueCross BlueShield, in September, disclosed an intrusion reaching back to December 2013 affecting roughly ten million people. Estimates vary on the overlap, but the 2014–2015 payer intrusions touched on the order of one hundred million Americans in under two years.

In June 2015, while Anthem's notification letters were still landing in mailboxes, the federal government disclosed the breach of the Office of Personnel Management: 21.5 million background-investigation files, including the exhaustive SF-86 questionnaires completed by everyone seeking a security clearance, plus millions of fingerprint records. The OPM intrusion was attributed to Chinese actors, and researchers noted overlaps in tooling with the health-insurer campaign.

Clearance files tell you who holds secrets, what they confessed on their forms, whom they know abroad, and what debts they carry. Insurance records fill in the rest of the population — addresses, family members, employers, incomes, Social Security numbers — and let an analyst cross-reference, verify, and find the people the clearance files miss. Later breaches slotted into the same picture: the Starwood reservation system at Marriott, disclosed in 2018 with hundreds of millions of guest records including travel histories, which American officials attributed to Chinese intelligence; and Equifax, for which the Justice Department indicted four members of China's People's Liberation Army in 2020. Whether every one of these operations served a single program is not something an outside observer can establish. What 2015 established is that a health insurer's membership file had become, to at least one foreign intelligence service, the same category of object as a credit bureau or a personnel agency: raw material for mapping a population.

Settlements and Fines

The legal reckoning ran five years and set records at every stage. In 2017 Anthem agreed to pay $115 million to settle the consolidated class actions — the largest data-breach settlement in American history at the time, granted final approval in August 2018. Class members were offered credit monitoring or modest cash payments, reimbursement of out-of-pocket losses, and the settlement bound Anthem to years of specified, audited security improvements. In October 2018 the company paid $16 million to the HHS Office for Civil Rights, roughly triple the previous record for a HIPAA settlement. OCR's findings are worth reading against the encryption debate, because encryption is not what the regulator cited: it found that Anthem had failed to conduct an adequate enterprise-wide risk analysis, had insufficient procedures for reviewing information-system activity, failed to identify and respond to suspected incidents, and failed to implement adequate minimum access controls — failures in the watching, not the wrapping, exactly where the company's own defense had pointed. In 2020 Anthem paid a further $39.5 million to settle with a coalition of forty-two state attorneys general and the District of Columbia, with California settling separately for $8.7 million.

The settlements together approached $180 million, and the insurance commissioners' examination reported that Anthem had spent roughly $260 million more on security improvements after the attack, a combined bill on the order of $400 million. The company, with annual revenue then approaching $80 billion, absorbed it without visible strain. The stock recovered quickly. The brand outlived the incident so completely that the company later shed it for unrelated reasons, renaming itself Elevance Health in 2022.

For the 78.8 million people in the warehouse, the accounting is harder to close, because the harm never took a form that could be measured. Victims of the great criminal breaches can at least watch for fraud; Anthem's victims were issued two years of credit monitoring to guard against an adversary that, on the evidence, had no interest in their credit. The Social Security numbers taken in 2014 are the same numbers those people carry today, because the American identity system offers no practical reissue. A child on a family policy in the warehouse that year entered adulthood with a permanent file — name, number, birth date, family, address history — held by a foreign intelligence service, and nothing in the class-action machinery, the OCR fine, or the credit-monitoring enrollment changed that.

What the Breach Established

Anthem is the least cinematic major breach in this book, and it is often reduced to a statistic for that reason.

Health insurers turned out to be intelligence targets, and the sector was slow to grasp it. Before 2015, healthcare security planning imagined criminals: billing fraud, identity theft, the resale of records. Anthem revealed a second adversary with different goals and different patience, one that wants the data itself, complete and quiet, and will spend eleven months getting it. A payer's master file is demographically closer to a census than to a customer list, and a census of Americans, joined to clearance files and travel records, is a strategic asset. No fraud model, and no compliance checklist built to prevent fraud, prices that adversary correctly. A year after Anthem's disclosure, ransomware crews began extorting hospitals openly — the subject of the chapter on Hollywood Presbyterian — and that crime wave's noise has obscured, ever since, the fact that the espionage never stopped.

Anthem's defense that encryption would not have helped was largely true, and it was also an admission of the real failure. Encryption at rest does not stop an attacker running queries with a stolen administrator's credentials. But the credentials were phishable, the privileged account could bulk-query tens of millions of rows without challenge, and the exfiltration of an entire warehouse crossed the network boundary unremarked. The controls that address a credentialed attacker — multi-factor authentication on administrative access, behavioral monitoring of privileged accounts, alerting on anomalous query volume, egress inspection — were the ones OCR found wanting. The encryption debate that followed the breach was largely beside the point; once an adversary owns an identity, every defense that trusts identity is already spent.

Eleven months of instrumentation did not detect the intrusion. One administrator glancing at a running query did, immediately and correctly. That an alert employee caught it proves the anomaly was visible all along, but detection that depends on the right person looking at the right screen in the right week is luck, not architecture. Credentials acting without their owner is exactly the signal that identity-analytics systems now exist to catch at machine speed, and Anthem's response shows what an institution can do once that signal reaches the right people: a low-level employee noticed something small and triggered a national-scale response within forty-eight hours.

Credit monitoring is the standard remedy for an American data breach, and against espionage it does little. It watches for the monetization of data by an adversary whose defining behavior is never monetizing it. The mismatch is also temporal: monitoring is sold in one- and two-year terms, while a Social Security number and a date of birth are permanent. Anthem's settlement was a record, and it purchased, for most class members, a service aimed at the wrong threat for a fraction of the exposure's life. That the American identity infrastructure, not the victim's vigilance, is what makes such breaches permanently harmful was not a conclusion regulators or legislators acted on in 2015, and it still has not been.

Data outlives the relationship that justified collecting it. The warehouse held more than twice Anthem's membership because nothing had ever been deleted. Every record retained past its purpose was pure downside the night the attackers reached the warehouse: former members and out-of-state claimants got all of the exposure and none of whatever service the retention theoretically enabled. Minimization and retention limits are usually argued as privacy compliance; Anthem is a case for arguing them as security engineering too, since the cheapest record to defend is the one no longer held.

The Anthem breach has no ending. The criminal cases elsewhere in this book resolve somehow — ransoms paid or refused, gangs disbanded, companies bankrupted, defendants sentenced. Anthem's indicted hacker is a photograph on a wanted poster; the stolen warehouse has never surfaced; the 78.8 million people it described have received everything the legal system had to give and remain exposed as they were on the morning of January 27, 2015. The collection presumably persists somewhere, merged and cross-referenced, useful to its owners in ways its subjects will never detect. The insurers hardened their networks and the regulators closed their files; American health data kept its new status as an object of statecraft.