CASE STUDY — NATION STATE APT

The Anthem Data Breach
Deep Panda — 2014–2015

The largest healthcare data breach in U.S. history. A Chinese state-sponsored threat actor spent nearly 12 months inside Anthem's network before being detected — exfiltrating 78.8 million unencrypted records.

78.8M
Records Stolen
~12 Months
Dwell Time
$131M+
Total Fines & Settlements
Deep Panda
Threat Actor (CrowdStrike)

Click each event to expand the full technical detail. The breach began 18 February 2014 — over 11 months before it was detected.

State-sponsored Chinese threat actor Deep Panda (also known as Axiom, Group 72, and Shell_Crew) achieves initial access to Anthem's corporate network. The entry vector was a spear-phishing email sent to a privileged system administrator. The phishing email delivered a variant of the Derusbi backdoor Trojan — digitally signed with the DTOPTOOLZ Co. certificate, a known Deep Panda calling card. This date was later confirmed by the Indiana Department of Insurance investigation as the true start of the breach.

MITRE ATT&CK TECHNIQUES

T1566.001 – Spear-phishing AttachmentT1195 – Supply Chain Compromise (fake VPN installer)

Sources: U.S. DOJ Indictment (May 2019) · KrebsOnSecurity · CrowdStrike Deep Panda attribution · Indiana DOI Investigation Report · HHS OCR Settlement · Wikipedia