A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that quietly stole personal data on 78.8 million people over the next 11 months.
Reviewed by the Social Engineering Examples team.
On February 4-5, 2015, Anthem publicly disclosed that a criminal cyberattacker had infiltrated its internally hosted enterprise data warehouse and stolen personal information on approximately 78.8 million current and former members and employees, at the time the largest healthcare-sector data breach in U.S. history. A multi-state insurance-commissioner examination (led by Indiana, with CrowdStrike and Alvarez & Marsal) and Anthem's own investigation by Mandiant traced the intrusion's origin to February 18, 2014, when an employee at an Anthem subsidiary opened a spear-phishing email containing malicious content. Data stolen (in unencrypted form) included names, dates of birth, Social Security numbers, healthcare/member ID numbers, home addresses, email addresses, phone numbers, and employment and income data. Anthem stated no medical claims or payment-card data were taken. The breach is confirmed and heavily documented across regulator settlements, a California DOJ judgment, and a 2019 DOJ indictment.
Opening the phishing email launched a download of malicious files to the employee's computer and gave the attackers remote access. From that foothold they moved laterally and escalated privileges, eventually operating with valid administrator-level credentials. The regulator report states the attacker used at least 50 accounts and compromised at least 90 systems, ultimately reaching the enterprise data warehouse that consolidated member data across Anthem's regional plans. Bulk queries were run against that warehouse (exfiltration occurring in the roughly Oct-Dec 2014 window) and archived data was transferred out. The intrusion succeeded and persisted because privileged remote access required only username/password (no two-factor), the network was insufficiently segmented, and security tooling either was not configured to alert on the anomalous activity or alerts (backdoor installs, network scanning, malware, unusual queries) went unactioned. Attribution rested on lookalike domains impersonating Anthem's old "Wellpoint" identity (we11point.com, with subdomains like myhr., hrsolutions., and extcitrix. mirroring real HR and Citrix VPN resources) and Sakula/Derusbi/Mivast malware signed with a DTOPTOOLZ certificate associated with the Deep Panda group.
The lure was a spear-phishing email delivered to subsidiary staff that pointed to attacker-controlled sites impersonating trusted internal resources (HR portals, remote-access/Citrix VPN pages) via a "we11point.com" lookalike domain, with the digits "11" standing in for the letters in "Wellpoint." The tell was the deceptive domain itself: a homoglyph/typosquat that looked like the company's own infrastructure but was not. Later, the operational tell that finally surfaced the breach was a database administrator noticing a query running under his own credentials that he had not initiated.
The intrusion went undetected for roughly 11 months until an Anthem database administrator noticed a data-warehouse query running under his own credentials on January 27, 2015; Anthem confirmed unauthorized access on/around January 29, notified the FBI, engaged Mandiant, and cut off the attacker within about three days. It disclosed publicly on Feb 4, 2015, offered credit protection to affected individuals, and made major security investments. Regulators concluded with high confidence they had identified the attacker and with medium confidence it acted on behalf of a foreign government. In May 2019 the DOJ unsealed a four-count indictment against PRC national Fujie Wang and a co-conspirator; Wang remains at large and wanted by the FBI.
Anthem is a canonical case showing that one employee's click at a subsidiary can cascade into the theft of tens of millions of records when credentials are reusable across a flat network. It demonstrates the nation-state PII-collection pattern (alongside OPM, Premera, and CareFirst) where medical/financial data is left untouched but durable personal identifiers are harvested for long-term intelligence use rather than immediate fraud. It also underscores that reasonable-sized security budgets don't help if privileged remote access lacks MFA, networks aren't segmented, and alerts aren't monitored: the exact controls Anthem was later ordered to implement.
Enforce phishing-resistant multi-factor authentication on all remote and privileged access; segment networks so a single subsidiary foothold cannot reach an enterprise-wide data warehouse; apply least-privilege and privileged-account management so admin credentials aren't broadly reusable; log and actively monitor for anomalous database queries, network scanning, backdoor installs, and access under idle/off-hours credentials; deploy email filtering plus recurring anti-phishing training and mock-phishing exercises; and monitor for lookalike/homoglyph domains impersonating your brand and internal portals (e.g., HR and VPN pages). Treat unexplained queries running under a legitimate user's identity as a high-priority alert.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked the Hong Kong subsidiary's finance controller into wiring $46.7M abroad…