CASE DOSSIER fugitive

U.S. v. Fujie Wang et al. (Anthem 78.8M Patient Record Breach)

Docket: 1:19-cr-00149 Court: U.S. District Court for the Southern District of Indiana Opened: 2015-02-04 Sector: Healthcare & Health Insurance

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$131.0 million
$115M consumer class settlement and $16M HHS OCR record HIPAA penalty.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Southern District of Indiana.
  • Primary Target Sector: Healthcare & Health Insurance.
  • Documented Financial Loss: $131.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Chinese state-affiliated threat actors conducted spearphishing campaigns against Anthem health insurance subsidiaries, deploying customized backdoors to penetrate enterprise data warehouses and exfiltrate 78.8 million personal health and identity records.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Targeted spearphishing campaign by Chinese state-sponsored actors against Anthem subsidiaries, masquerading as internal HR and IT communications to deploy backdoors and harvest database administrator credentials.

Operational & Financial Fallout

Exfiltration of 78.8 million records containing names, Social Security numbers, dates of birth, healthcare ID numbers, home addresses, and employment details, making it the largest healthcare data breach in history and resulting in a $115M class action settlement and $16M HHS OCR fine.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Targeted spearphishing campaign by Chinese state-sponsored actors against Anthem subsidiaries, masquerading as internal HR and IT communications to deploy backdoors and harvest database administrator credentials.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Spearphishing Infiltration
MITRE ATT&CK T1566.002 →

Phishing emails carrying malicious attachments or spoofed domain links delivered backdoors to employee workstation endpoints.

Artifacts & Tooling: Spoofed HR emails Malicious link payloads
2
Command & Control Backdoor Installation & C2 Callback
MITRE ATT&CK T1071.001 →

Custom RATs (including Sakula and Derusbi) executed on victim endpoints, establishing encrypted communication channels to foreign C2 nodes.

Artifacts & Tooling: Sakula RAT Derusbi backdoor Encrypted C2 beacons
3
Credential Dumping High-Privilege Credential Dumping
MITRE ATT&CK T1003 →

Adversaries used memory scraping tools to capture credentials of database administrators with access to the enterprise data warehouse.

Artifacts & Tooling: Memory scraper Captured DBA credentials
4
Data Collection Structured SQL Query Exfiltration
MITRE ATT&CK T1530 →

Threat actors queried the unencrypted Oracle enterprise data warehouse containing tens of millions of health plan subscriber records.

Artifacts & Tooling: Bulk SQL SELECT statements Oracle data warehouse dumps
5
Exfiltration Compressed Encrypted Staging & Export
MITRE ATT&CK T1048 →

Data was partitioned into compressed, password-protected archives and exfiltrated via encrypted SSL sessions to external adversary servers.

Artifacts & Tooling: Encrypted ZIP archives Outbound SSL tunnels
Real-World Blast Radius & Operational Fallout

Exfiltration of 78.8 million records containing names, Social Security numbers, dates of birth, healthcare ID numbers, home addresses, and employment details, making it the largest healthcare data breach in history and resulting in a $115M class action settlement and $16M HHS OCR fine.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Implement column-level and tablespace-level encryption for databases storing personally identifiable information (PII).
✓ Deploy behavioral anomaly detection to flag bulk database queries exceeding historical operational baselines.
✓ Enforce hardware token MFA on all privileged database administration accounts.
✓ Monitor outbound connections for anomalous encrypted data transfers originating from internal database clusters.

Procedural & Incident Timeline

2014-04-18 incident

Initial spearphishing compromise establishes persistent foothold in Anthem network.

2015-01-27 discovery

Anthem database administrator notices unauthorized database query executing with administrator credentials.

2019-05-09 indictment

DOJ unseals indictment charging Chinese national Fujie Wang for Anthem intrusion.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.002 Spearphishing Link
Initial Access
"Defendants sent spearphishing emails to Anthem subsidiary personnel containing hyperlinks that downloaded malicious executable payloads disguised as corporate software." Indictment ¶ 14, Page 6 reviewed
T1078 Valid Accounts
Defense Evasion
"After compromising a database administrator account, the hackers used valid credentials to run SQL queries querying millions of rows from the data warehouse." Indictment ¶ 22, Page 9 reviewed
T1560
"Defendants compressed extracted database tables into password-protected encrypted RAR archives to evade egress network pattern detection." Indictment ¶ 28, Page 11 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Fujie Wang et al. (Anthem 78.8M Patient Record Breach), No. 1:19-cr-00149 (U.S. District Court for the Southern District of Indiana 2015), https://cybercaselibrary.com/cases/anthem-health-insurance-data-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/anthem-health-insurance-data-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>