HomeSecurityAnthem Breach State attack or cyber robbery?

Anthem Breach: State Attack or Cyber ​​Robbery?

The breach is probably the largest healthcare hack we've seen, with 80 million people reportedly affected, with their personal information exposed to unauthorized individuals.Anthem hack

While a clear picture has not yet been formed as researchers are still collecting pieces of the puzzle, the first conclusion seems to point to China as the place of origin of the attack.

A project sponsored by a state or the work of criminals whose goal was financial gain?

Anthem is the second largest insurance provider in the US and offers services to an impressive number of customers, including workers in sensitive sectors, such as the country's defense, but also in government organizations in general .

Northrop Grumman Corporation, a global aerospace and defense technology company, uses Anthem's services to provide insurance coverage for its employees. Anthem's client list also includes The Boeing Company, which also has a defense unit.

With this information, the scenario of a targeted attack by a foreign government seems to make sense.

In an official statement presenting the incident, Joseph Swedish, Anthem's president and CEO, said that the leaked customer data included names, birthdays, medical IDs, Social Security Numbers (SSNs), addresses, email addresses, and employment and income details.

He called the breach a “very sophisticated external attack,” suggesting that a highly skilled group of hackers, backed by rich resources, may be behind the hack.

According to The Wall Street Journal, researchers say the Anthem hack was carried out using malware that appears to have been used almost exclusively by Chinese cyberspies.

Attacking Anthem's systems is no amateur job, that's for sure.

Reports from multiple news outlets indicate that Anthem data stored on the system was not encrypted, highlighting the fact that attackers could have accessed plain text files.

Encryption is used to protect stored information, as well as during transmission from the client to the server. This ensures that unauthorized individuals cannot exploit the information even if they have it in their hands, or at least can exploit it less.

However, according to Anthem, there was unauthorized activity on administrator log-in credentials from December 10, 2014, which continued sporadically until January 27, 2015. The company's investigation showed that log-in credentials from multiple administrators had changed hands.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS