{
  "id": "case-anthem-breach",
  "slug": "anthem-health-insurance-data-breach",
  "title": "U.S. v. Fujie Wang et al. (Anthem 78.8M Patient Record Breach)",
  "summary": "Chinese state-affiliated threat actors conducted spearphishing campaigns against Anthem health insurance subsidiaries, deploying customized backdoors to penetrate enterprise data warehouses and exfiltrate 78.8 million personal health and identity records.",
  "case_number": "1:19-cr-00149",
  "court": "U.S. District Court for the Southern District of Indiana",
  "district": "S.D. Ind.",
  "country": "United States",
  "opened_at": "2015-02-04",
  "status": "fugitive",
  "victim_sector": "Healthcare & Health Insurance",
  "victim_country": "United States",
  "loss_amount_usd": 131000000,
  "loss_amount_note": "$115M consumer class settlement and $16M HHS OCR record HIPAA penalty.",
  "first_seen_at": "2014-04-18T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "deep-panda",
  "defendant_slugs": [
    "fujie-wang"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Defendants sent spearphishing emails to Anthem subsidiary personnel containing hyperlinks that downloaded malicious executable payloads disguised as corporate software.",
      "evidence_locator": "Indictment \u00b6 14, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Fujie Wang",
      "source_url": "https://www.justice.gov/opa/pr/member-sophisticated-china-based-hacking-group-indicted-series-computer-intrusions-including",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "After compromising a database administrator account, the hackers used valid credentials to run SQL queries querying millions of rows from the data warehouse.",
      "evidence_locator": "Indictment \u00b6 22, Page 9",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1560",
      "evidence_excerpt": "Defendants compressed extracted database tables into password-protected encrypted RAR archives to evade egress network pattern detection.",
      "evidence_locator": "Indictment \u00b6 28, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2014-04-18",
      "description": "Initial spearphishing compromise establishes persistent foothold in Anthem network."
    },
    {
      "event_type": "discovery",
      "event_date": "2015-01-27",
      "description": "Anthem database administrator notices unauthorized database query executing with administrator credentials."
    },
    {
      "event_type": "indictment",
      "event_date": "2019-05-09",
      "description": "DOJ unseals indictment charging Chinese national Fujie Wang for Anthem intrusion."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Targeted spearphishing campaign by Chinese state-sponsored actors against Anthem subsidiaries, masquerading as internal HR and IT communications to deploy backdoors and harvest database administrator credentials.",
    "blast_radius": "Exfiltration of 78.8 million records containing names, Social Security numbers, dates of birth, healthcare ID numbers, home addresses, and employment details, making it the largest healthcare data breach in history and resulting in a $115M class action settlement and $16M HHS OCR fine.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Spearphishing Infiltration",
        "description": "Phishing emails carrying malicious attachments or spoofed domain links delivered backdoors to employee workstation endpoints.",
        "technical_artifacts": [
          "Spoofed HR emails",
          "Malicious link payloads"
        ],
        "mitre_technique_id": "T1566.002"
      },
      {
        "phase": "Command & Control",
        "title": "Backdoor Installation & C2 Callback",
        "description": "Custom RATs (including Sakula and Derusbi) executed on victim endpoints, establishing encrypted communication channels to foreign C2 nodes.",
        "technical_artifacts": [
          "Sakula RAT",
          "Derusbi backdoor",
          "Encrypted C2 beacons"
        ],
        "mitre_technique_id": "T1071.001"
      },
      {
        "phase": "Credential Dumping",
        "title": "High-Privilege Credential Dumping",
        "description": "Adversaries used memory scraping tools to capture credentials of database administrators with access to the enterprise data warehouse.",
        "technical_artifacts": [
          "Memory scraper",
          "Captured DBA credentials"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Data Collection",
        "title": "Structured SQL Query Exfiltration",
        "description": "Threat actors queried the unencrypted Oracle enterprise data warehouse containing tens of millions of health plan subscriber records.",
        "technical_artifacts": [
          "Bulk SQL SELECT statements",
          "Oracle data warehouse dumps"
        ],
        "mitre_technique_id": "T1530"
      },
      {
        "phase": "Exfiltration",
        "title": "Compressed Encrypted Staging & Export",
        "description": "Data was partitioned into compressed, password-protected archives and exfiltrated via encrypted SSL sessions to external adversary servers.",
        "technical_artifacts": [
          "Encrypted ZIP archives",
          "Outbound SSL tunnels"
        ],
        "mitre_technique_id": "T1048"
      }
    ],
    "defensive_takeaways": [
      "Implement column-level and tablespace-level encryption for databases storing personally identifiable information (PII).",
      "Deploy behavioral anomaly detection to flag bulk database queries exceeding historical operational baselines.",
      "Enforce hardware token MFA on all privileged database administration accounts.",
      "Monitor outbound connections for anomalous encrypted data transfers originating from internal database clusters."
    ]
  }
}