Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatmass-credential-exposurestate-sponsored-espionage

Anthem Breach Exposed Personal Data of Up to 80 Million Health Plan Members

Updated 1mo agoFirst seen May 25, 20265 sources

Anthem disclosed that attackers breached its systems and stole personal information tied to as many as 80 million current and former members and employees, making the incident one of the largest healthcare data breaches on record. The company said a sophisticated external attack exposed names, birth dates, medical or member IDs, Social Security numbers, street addresses, email addresses, phone numbers, and employment and income information across multiple Anthem brands, including Anthem Blue Cross, Empire Blue Cross and Blue Shield, Amerigroup, Caremore, Unicare, Healthlink, and DeCare. Anthem said there was no evidence that credit card data or medical records such as claims, test results, or diagnostic codes were taken.

The insurer said it discovered the intrusion, notified the FBI, hired Mandiant to conduct a forensic investigation, and planned to offer affected individuals free credit monitoring and identity protection services. Reporting said the compromised database was not encrypted at rest and that investigators were examining whether the attackers used stolen administrator credentials, with some scrutiny falling on possible links to Chinese cyberespionage activity. The breach also underscored a broader surge in attacks on healthcare organizations, where rich stores of personally identifiable information had made the sector an increasingly attractive target for cybercriminals.

Share:
Anthem Breach Exposed Personal Data of Up to 80 Million Health Plan Members
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 22, 201511y ago

State attorneys general and FBI investigate Anthem breach

Following the breach disclosure, multiple U.S. state attorneys general opened investigations and the FBI continued its inquiry. Reporting also said investigators were examining possible links to China and tools associated with Chinese cyberespionage groups.

Anthem says affected customer data was not encrypted at rest

Subsequent reporting said the breached Anthem database was not encrypted at rest and that attackers had bypassed security protocols by compromising an administrator's credentials. Anthem argued HIPAA did not specifically require encryption and said other controls had been in place.

Feb 4, 201511y ago

Anthem publicly discloses breach affecting about 80 million people

On February 4, 2015, Anthem disclosed that attackers accessed a database containing records for roughly 80 million current and former members and employees. Exposed data included names, birth dates, medical IDs or Social Security numbers, addresses, email addresses, and employment and income information, while Anthem said no credit card or medical claims data appeared compromised.

Anthem discovers major cyberattack and notifies the FBI

Anthem said it discovered a sophisticated external cyberattack against its systems and notified law enforcement, including the FBI. The company also retained Mandiant to investigate and assess its systems.

Dec 31, 201411y ago

More than 10 million affected by healthcare breaches in 2014

According to the U.S. Department of Health and Human Services as cited by the Boston Globe, more than 10 million people were affected by healthcare data breaches in the prior year. The article frames this as part of a broader rise in cybercrime targeting the healthcare sector.

Dec 31, 201115y ago

Healthcare breaches affect more than 11 million people in 2011

The Boston Globe reference says 2011 had been the worst year for healthcare hacking up to that point, with more than 11 million people affected. This provides earlier sector context for the later Anthem incident.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Anthem Breach Exposed Personal Data of Up to 80 Million Health Plan Members | Mallory