First reportedFebruary 4, 2015
ActivityActivity date not specified
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencehigh

Key facts

Affected

  • Anthem members and former members
  • Anthem, Inc.

Initial access

  • unknown

Impact

  • data_theft
  • financial_loss

Attribution

unknown med confidence

DOJ announced charges against an alleged member of a China-based hacking group connected to the Anthem breach; final legal outcomes may vary by defendant and are not summarized here.

CVEs and ATT&CK

No CVE or ATT&CK association is captured in this curated record.

Mitigations

Now

  • Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.

Soon

  • Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.

Later

  • Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.

Detection ideas

Alert on anomalous authentication patterns

Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.

Data sources: IdP sign-in logs, SSO audit logs, VPN authentication logs

Detect risky account recovery and MFA changes

Alert when MFA factors are reset/added, recovery email/phone is changed, or helpdesk performs high-risk password resets outside normal hours.

Data sources: IdP audit logs, Helpdesk/ticketing logs

Sources