U.S. v. Fujie Wang et al. (Anthem 78.8M Patient Record Breach)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Southern District of Indiana.
- Primary Target Sector: Healthcare & Health Insurance.
- Documented Financial Loss: $131.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Targeted spearphishing campaign by Chinese state-sponsored actors against Anthem subsidiaries, masquerading as internal HR and IT communications to deploy backdoors and harvest database administrator credentials.
Operational & Financial Fallout
Exfiltration of 78.8 million records containing names, Social Security numbers, dates of birth, healthcare ID numbers, home addresses, and employment details, making it the largest healthcare data breach in history and resulting in a $115M class action settlement and $16M HHS OCR fine.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Targeted spearphishing campaign by Chinese state-sponsored actors against Anthem subsidiaries, masquerading as internal HR and IT communications to deploy backdoors and harvest database administrator credentials.
Adversary Kill Chain Flow
5 Documented PhasesPhishing emails carrying malicious attachments or spoofed domain links delivered backdoors to employee workstation endpoints.
Custom RATs (including Sakula and Derusbi) executed on victim endpoints, establishing encrypted communication channels to foreign C2 nodes.
Adversaries used memory scraping tools to capture credentials of database administrators with access to the enterprise data warehouse.
Threat actors queried the unencrypted Oracle enterprise data warehouse containing tens of millions of health plan subscriber records.
Data was partitioned into compressed, password-protected archives and exfiltrated via encrypted SSL sessions to external adversary servers.
Exfiltration of 78.8 million records containing names, Social Security numbers, dates of birth, healthcare ID numbers, home addresses, and employment details, making it the largest healthcare data breach in history and resulting in a $115M class action settlement and $16M HHS OCR fine.
Procedural & Incident Timeline
Initial spearphishing compromise establishes persistent foothold in Anthem network.
Anthem database administrator notices unauthorized database query executing with administrator credentials.
DOJ unseals indictment charging Chinese national Fujie Wang for Anthem intrusion.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.002 | Spearphishing Link Initial Access | "Defendants sent spearphishing emails to Anthem subsidiary personnel containing hyperlinks that downloaded malicious executable payloads disguised as corporate software." | Indictment ¶ 14, Page 6 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "After compromising a database administrator account, the hackers used valid credentials to run SQL queries querying millions of rows from the data warehouse." | Indictment ¶ 22, Page 9 | reviewed |
| T1560 | "Defendants compressed extracted database tables into password-protected encrypted RAR archives to evade egress network pattern detection." | Indictment ¶ 28, Page 11 | reviewed |