A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data on 78.8 million people.
Social Engineering Examples·8 sources
On February 4-5, 2015, Anthem publicly disclosed that a criminal cyberattacker had infiltrated its internally hosted enterprise data warehouse and stolen personal information on approximately 78.8 million current and former members and employees, at the time the largest healthcare-sector data breach in U.S. history. A multi-state insurance-commissioner examination (led by Indiana, with CrowdStrike and Alvarez & Marsal) and Anthem's own investigation by Mandiant traced the intrusion's origin to February 18, 2014, when an employee at an Anthem subsidiary opened a spear-phishing email containing malicious content.
Data stolen (in unencrypted form) included names, dates of birth, Social Security numbers, healthcare/member ID numbers, home addresses, email addresses, phone numbers, and employment and income data. Anthem stated no medical claims or payment-card data were taken. The breach is confirmed and heavily documented across regulator settlements, a California DOJ judgment, and a 2019 DOJ indictment.
Opening the phishing email launched a download of malicious files to the employee's computer and gave the attackers remote access. From that foothold they moved laterally and escalated privileges, eventually operating with valid administrator-level credentials. The regulator report states the attacker used at least 50 accounts and compromised at least 90 systems, ultimately reaching the enterprise data warehouse that consolidated member data across Anthem's regional plans.
Bulk queries were run against that warehouse (exfiltration occurring in the roughly Oct-Dec 2014 window) and archived data was transferred out. The intrusion succeeded and persisted because privileged remote access required only username/password (no two-factor), the network was insufficiently segmented, and security tooling either was not configured to alert on the anomalous activity or alerts (backdoor installs, network scanning, malware, unusual queries) went unactioned.
Attribution rested on lookalike domains impersonating Anthem's old "Wellpoint" identity (we11point.com, with subdomains like myhr., hrsolutions., and extcitrix. mirroring real HR and Citrix VPN resources) and Sakula/Derusbi/Mivast malware signed with a DTOPTOOLZ certificate associated with the Deep Panda group.
The lure was a spear-phishing email delivered to subsidiary staff that pointed to attacker-controlled sites impersonating trusted internal resources (HR portals, remote-access/Citrix VPN pages) via a "we11point.com" lookalike domain, with the digits "11" standing in for the letters in "Wellpoint." The tell was the deceptive domain itself: a homoglyph/typosquat that looked like the company's own infrastructure but was not.
Later, the operational tell that finally surfaced the breach was a database administrator noticing a query running under his own credentials that he had not initiated.
The intrusion went undetected for roughly 11 months until an Anthem database administrator noticed a data-warehouse query running under his own credentials on January 27, 2015; Anthem confirmed unauthorized access on/around January 29, notified the FBI, engaged Mandiant, and cut off the attacker within about three days. It disclosed publicly on Feb 4, 2015, offered credit protection to affected individuals, and made major security investments.
Regulators concluded with high confidence they had identified the attacker and with medium confidence it acted on behalf of a foreign government. In May 2019 the DOJ unsealed a four-count indictment against PRC national Fujie Wang and a co-conspirator; Wang remains at large and wanted by the FBI.
Anthem is a canonical case showing that one employee's click at a subsidiary can cascade into the theft of tens of millions of records when credentials are reusable across a flat network. It demonstrates the nation-state PII-collection pattern (alongside OPM, Premera, and CareFirst) where medical/financial data is left untouched but durable personal identifiers are harvested for long-term intelligence use rather than immediate fraud.
It also underscores that reasonable-sized security budgets don't help if privileged remote access lacks MFA, networks aren't segmented, and alerts aren't monitored: the exact controls Anthem was later ordered to implement.
Enforce phishing-resistant multi-factor authentication on all remote and privileged access; segment networks so a single subsidiary foothold cannot reach an enterprise-wide data warehouse; apply least-privilege and privileged-account management so admin credentials aren't broadly reusable; log and actively monitor for anomalous database queries, network scanning, backdoor installs, and access under idle/off-hours credentials; deploy email filtering plus recurring anti-phishing training and mock-phishing exercises; and monitor for lookalike/homoglyph domains impersonating your brand and internal portals (e.g., HR and VPN pages).
Treat unexplained queries running under a legitimate user's identity as a high-priority alert.
Social Engineering Examples. “Anthem health-insurer breach (78.8M records)”. Accessed 19 September 2026. https://socialengineeringexamples.com/anthem-health-insurer-breach-2015
Deep Panda/Black Vine is documented by CrowdStrike and Symantec as a long-running Chinese cyberespionage group that ran multiple healthcare, energy, and aerospace campaigns around this period; consistent with that pattern, the operators likely used OSINT on Anthem's subsidiary staff and its then-current Wellpoint-era branding to identify a plausible employee target and build convincing internal-looking lure content.
Employee-facing OSINT exposure and legacy-brand knowledge are very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this and hardens the process it gets used against, the email-filtering and training control at Stage 3, rather than trying to hide it.
per KrebsOnSecurity and ThreatConnect's forensic analysis, the group stood up look-alike domain infrastructure, the we11point.com typosquat and subdomains mimicking Anthem's real HR portal and Citrix VPN, and used malware digitally signed with a DTOPTOOLZ certificate that CrowdStrike ties to Deep Panda, the toolkit documented as characteristic of this campaign.
Domain and certificate-transparency monitoring for look-alike/homoglyph registrations of a company's own brand and internal portal names (HR, VPN) can catch typosquats like we11point.com at or shortly after registration, a control the California AG's final judgment specifically required Anthem to add.
on February 18, 2014, an employee at an Anthem subsidiary opened a spear-phishing email containing malicious content; per the multistate regulatory examination and Anthem's own Mandiant investigation, opening it triggered a malware download that gave the attacker remote access to that employee's computer.
Email filtering plus recurring anti-phishing training and mock-phishing exercises, exactly what the CA AG's final judgment ordered Anthem to implement, reduces the odds a single spear-phishing email reaches or fools an employee.
from that single foothold the attacker moved across the network, per the regulators' report ultimately using at least 50 accounts and compromising at least 90 systems, escalating to valid administrator-level credentials along the way.
Phishing-resistant MFA on remote and privileged access, network segmentation, and least-privilege/privileged-access management stop one compromised endpoint's credentials from reaching dozens of accounts and systems, the exact gap regulators cited as missing.
the attacker used those credentials to reach the data warehouse consolidating member records across Anthem's regional plans and ran bulk queries against it, exfiltration activity the regulatory report places in roughly the October-December 2014 window.
Active logging and alerting on anomalous database queries and access under idle or off-hours credentials, treating any query run under a legitimate user's identity that they did not initiate as a high-priority alert, is the same anomaly that eventually surfaced this breach.
archived query results were transferred out, ultimately yielding records on 78.8 million people; consistent with the nation-state PII-collection pattern regulators described, no immediate fraud followed, indicating the payout was durable personal data for longer-term intelligence use rather than a financial cash-out.
Data-loss-prevention and egress monitoring for unusual bulk outbound transfers from a data warehouse can flag exfiltration in progress; absent that, the realistic backstop is the Stage 5 alerting, since by this point the intrusion objective is already substantially complete.
Browse by what this case has in common with others in the library.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO demanded an urgent transfer.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…