
The largest healthcare data breach in U.S. history. A Chinese state-sponsored threat actor spent nearly 12 months inside Anthem's network before being detected — exfiltrating 78.8 million unencrypted records.
Click each event to expand the full technical detail. The breach began 18 February 2014 — over 11 months before it was detected.
State-sponsored Chinese threat actor Deep Panda (also known as Axiom, Group 72, and Shell_Crew) achieves initial access to Anthem's corporate network. The entry vector was a spear-phishing email sent to a privileged system administrator. The phishing email delivered a variant of the Derusbi backdoor Trojan — digitally signed with the DTOPTOOLZ Co. certificate, a known Deep Panda calling card. This date was later confirmed by the Indiana Department of Insurance investigation as the true start of the breach.
MITRE ATT&CK TECHNIQUES
Sources: U.S. DOJ Indictment (May 2019) · KrebsOnSecurity · CrowdStrike Deep Panda attribution · Indiana DOI Investigation Report · HHS OCR Settlement · Wikipedia