Chinese state-affiliated threat actors conducted spearphishing campaigns against Anthem health insurance subsidiaries, deploying customized backdoors to penetrate enterprise data warehouses and exfiltrate 78.8 million personal health and identity records.