A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data on 78.8 million people.
Social Engineering Examples·8 sources
On February 4-5, 2015, Anthem publicly disclosed that a criminal cyberattacker had infiltrated its internally hosted enterprise data warehouse and stolen personal information on approximately 78.8 million current and former members and employees, at the time the largest healthcare-sector data breach in U.S. history. A multi-state insurance-commissioner examination (led by Indiana, with CrowdStrike and Alvarez & Marsal) and Anthem's own investigation by Mandiant traced the intrusion's origin to February 18, 2014, when an employee at an Anthem subsidiary opened a spear-phishing email containing malicious content.
Data stolen (in unencrypted form) included names, dates of birth, Social Security numbers, healthcare/member ID numbers, home addresses, email addresses, phone numbers, and employment and income data. Anthem stated no medical claims or payment-card data were taken. The breach is confirmed and heavily documented across regulator settlements, a California DOJ judgment, and a 2019 DOJ indictment.
Opening the phishing email launched a download of malicious files to the employee's computer and gave the attackers remote access. From that foothold they moved laterally and escalated privileges, eventually operating with valid administrator-level credentials. The regulator report states the attacker used at least 50 accounts and compromised at least 90 systems, ultimately reaching the enterprise data warehouse that consolidated member data across Anthem's regional plans.
Bulk queries were run against that warehouse (exfiltration occurring in the roughly Oct-Dec 2014 window) and archived data was transferred out. The intrusion succeeded and persisted because privileged remote access required only username/password (no two-factor), the network was insufficiently segmented, and security tooling either was not configured to alert on the anomalous activity or alerts (backdoor installs, network scanning, malware, unusual queries) went unactioned.
Attribution rested on lookalike domains impersonating Anthem's old "Wellpoint" identity (we11point.com, with subdomains like myhr., hrsolutions., and extcitrix. mirroring real HR and Citrix VPN resources) and Sakula/Derusbi/Mivast malware signed with a DTOPTOOLZ certificate associated with the Deep Panda group.
The lure was a spear-phishing email delivered to subsidiary staff that pointed to attacker-controlled sites impersonating trusted internal resources (HR portals, remote-access/Citrix VPN pages) via a "we11point.com" lookalike domain, with the digits "11" standing in for the letters in "Wellpoint." The tell was the deceptive domain itself: a homoglyph/typosquat that looked like the company's own infrastructure but was not.
Later, the operational tell that finally surfaced the breach was a database administrator noticing a query running under his own credentials that he had not initiated.
The intrusion went undetected for roughly 11 months until an Anthem database administrator noticed a data-warehouse query running under his own credentials on January 27, 2015; Anthem confirmed unauthorized access on/around January 29, notified the FBI, engaged Mandiant, and cut off the attacker within about three days. It disclosed publicly on Feb 4, 2015, offered credit protection to affected individuals, and made major security investments.
Regulators concluded with high confidence they had identified the attacker and with medium confidence it acted on behalf of a foreign government. In May 2019 the DOJ unsealed a four-count indictment against PRC national Fujie Wang and a co-conspirator; Wang remains at large and wanted by the FBI.
Anthem is a canonical case showing that one employee's click at a subsidiary can cascade into the theft of tens of millions of records when credentials are reusable across a flat network. It demonstrates the nation-state PII-collection pattern (alongside OPM, Premera, and CareFirst) where medical/financial data is left untouched but durable personal identifiers are harvested for long-term intelligence use rather than immediate fraud.
It also underscores that reasonable-sized security budgets don't help if privileged remote access lacks MFA, networks aren't segmented, and alerts aren't monitored: the exact controls Anthem was later ordered to implement.
Enforce phishing-resistant multi-factor authentication on all remote and privileged access; segment networks so a single subsidiary foothold cannot reach an enterprise-wide data warehouse; apply least-privilege and privileged-account management so admin credentials aren't broadly reusable; log and actively monitor for anomalous database queries, network scanning, backdoor installs, and access under idle/off-hours credentials; deploy email filtering plus recurring anti-phishing training and mock-phishing exercises; and monitor for lookalike/homoglyph domains impersonating your brand and internal portals (e.g., HR and VPN pages).
Treat unexplained queries running under a legitimate user's identity as a high-priority alert.
Social Engineering Examples. “Anthem health-insurer breach (78.8M records)”. Accessed 14 September 2026. https://socialengineeringexamples.com/anthem-health-insurer-breach-2015
Deep Panda/Black Vine is documented by CrowdStrike and Symantec as a long-running Chinese cyberespionage group that ran multiple healthcare, energy, and aerospace campaigns around this period; consistent with that pattern, the operators likely used OSINT on Anthem's subsidiary staff and its then-current Wellpoint-era branding to identify a plausible employee target and build convincing internal-looking lure content.
Employee-facing OSINT exposure and legacy-brand knowledge are very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this and hardens the process it gets used against, the email-filtering and training control at Stage 3, rather than trying to hide it.
per KrebsOnSecurity and ThreatConnect's forensic analysis, the group stood up look-alike domain infrastructure, the we11point.com typosquat and subdomains mimicking Anthem's real HR portal and Citrix VPN, and used malware digitally signed with a DTOPTOOLZ certificate that CrowdStrike ties to Deep Panda, the toolkit documented as characteristic of this campaign.
Domain and certificate-transparency monitoring for look-alike/homoglyph registrations of a company's own brand and internal portal names (HR, VPN) can catch typosquats like we11point.com at or shortly after registration, a control the California AG's final judgment specifically required Anthem to add.
on February 18, 2014, an employee at an Anthem subsidiary opened a spear-phishing email containing malicious content; per the multistate regulatory examination and Anthem's own Mandiant investigation, opening it triggered a malware download that gave the attacker remote access to that employee's computer.
Email filtering plus recurring anti-phishing training and mock-phishing exercises, exactly what the CA AG's final judgment ordered Anthem to implement, reduces the odds a single spear-phishing email reaches or fools an employee.
from that single foothold the attacker moved across the network, per the regulators' report ultimately using at least 50 accounts and compromising at least 90 systems, escalating to valid administrator-level credentials along the way.
Phishing-resistant MFA on remote and privileged access, network segmentation, and least-privilege/privileged-access management stop one compromised endpoint's credentials from reaching dozens of accounts and systems, the exact gap regulators cited as missing.
the attacker used those credentials to reach the data warehouse consolidating member records across Anthem's regional plans and ran bulk queries against it, exfiltration activity the regulatory report places in roughly the October-December 2014 window.
Active logging and alerting on anomalous database queries and access under idle or off-hours credentials, treating any query run under a legitimate user's identity that they did not initiate as a high-priority alert, is the same anomaly that eventually surfaced this breach.
archived query results were transferred out, ultimately yielding records on 78.8 million people; consistent with the nation-state PII-collection pattern regulators described, no immediate fraud followed, indicating the payout was durable personal data for longer-term intelligence use rather than a financial cash-out.
Data-loss-prevention and egress monitoring for unusual bulk outbound transfers from a data warehouse can flag exfiltration in progress; absent that, the realistic backstop is the Stage 5 alerting, since by this point the intrusion objective is already substantially complete.
Browse by what this case has in common with others in the library.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
Researchers from UIUC, the University of Michigan, and Google dropped 297 USB drives across the UIUC campus and found that…
In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a…
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
In the same January 12, 2010 blog post disclosing Operation Aurora, Google revealed that dozens of Gmail accounts belonging to…
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…