Breach report
HealthcareAnthem (now Elevance Health)
Health Insurance Provider Anthem Reports Massive Data Breach
Hackers suspected of working for China spent weeks inside Anthem's network and stole Social Security numbers and other personal details on 78.8 million current and former members, the largest U.S. health insurer breach at the time.
Reported by TechCrunch
Records exposed
78.8M
78.8 million people
Scale vs. largest on file
- When
- 2014 (disclosed 2015)
- How they got in
- Spear-phishing leading to compromise of a corporate data warehouse (suspected state-sponsored)
- Sector
- Healthcare
In early February 2015, Anthem, then the second-largest health insurer in the United States, announced that attackers had broken into a database holding records on tens of millions of current and former customers and employees. The company later settled on a total of about 78.8 million people, spanning Anthem Blue Cross and Blue Shield plans, Amerigroup, Empire Blue Cross and several other brands, along with members of other Blue Cross plans who had used Anthem's network. It was the largest healthcare breach ever reported in the United States at the time, roughly double the size of the Target retail breach.
Investigators traced the intrusion to spear-phishing emails sent to employees of an Anthem subsidiary as early as February 2014. After at least one worker opened a malicious message, the attackers harvested credentials, moved laterally and eventually reached a data warehouse, which they queried and exfiltrated between December 2014 and late January 2015. An Anthem database administrator noticed a suspicious query running under his own credentials, which led to discovery.
The stolen records included names, birthdates, Social Security numbers, member IDs, addresses, email addresses and employment and income details. Anthem said medical claims and payment card data were not taken. The company brought in Mandiant, notified the FBI and offered affected people free credit monitoring.
The legal and regulatory consequences stretched over years. Anthem agreed to a $115 million class-action settlement, then the largest for a data breach, and in 2018 paid $16 million to the U.S. Department of Health and Human Services to resolve HIPAA violations, a record at the time. A coalition of state attorneys general reached a further $39.5 million settlement in 2020. In 2019 the U.S. Justice Department indicted two Chinese nationals, alleging they were part of a hacking group behind the Anthem intrusion and others.
The breach is widely viewed as part of a campaign by Chinese state-linked hackers to build dossiers on Americans, alongside intrusions at the Office of Personnel Management and elsewhere. Because Social Security numbers and birthdates cannot be changed, the exposure has long-term value for identity theft and intelligence targeting. The case pushed health insurers to encrypt data at rest, tighten privileged access and invest in phishing-resistant authentication.