18 ms·
“Anthem was the target of a very sophisticated external cyber attack”
- emeidi 12y agoHigh five to all the CISAs, CISMs, CGEITs, CRISCs and CISSPs at Anthem.
- harkyns_castle 12y agoMakes you wonder doesn't it, the dollars that got spent to have something blatant happen. Its not an industry I'd like to be in, with everything so compromised.
- Slartibreakfast 12y agoIt's important to remember that many of the security folks at these companies are actually pretty good. This is more of a C-Suite problem than a security team problem - security people can't get much done if senior management doesn't prioritize a good information security program.
- Bud 12y agoGreeeeeeeeat. Anthem just became my health care provider. This fills me with confidence. I'm especially unimpressed by Anthem's failure to hire a good copy editor for such a vital message, as evidenced by the painfully obvious error at the end of the penultimate paragraph: "share that information you" should read "share that information with you".
- jgeorge 12y agoMy new health care provider as of January 1st!</yay>
- kevinchau 12y agoI hate the tone of that letter, has the typical PR tone all over it. Basically to sum it up: "Your Social Security Number, Name, Birthdate, Address, and everything else needed to steal your identity is at risk. But don't worry! Your credit card number is safe."
- dubyah 12y agoThey stopped taking automatic credit card payments ~3.5 years ago, so even that last bit isn't much of an accomplishment.
- jamra 12y agoThey also use a different company to do payments for them. That is likely why they said what they said.
- prawn 12y agoAnd listing income data last, like they're hoping members don't notice it.
- jakejohns 12y agoThe whois[1] records for http://anthemfacts.com http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier. [1] http://whois.icann.org/en/lookup?name=anthemfacts.com http://whois.icann.org/en/lookup?name=anthemfacts.com
- valgaze 12y agoTHAT is some clever detective work! To give 'em the benefit of the doubt-- perhaps perhaps perhaps they needed that particular domain in anticipation of some other instance where they dropped the ball but your conclusion is more compelling.
- thirsteh 12y agoThey recently changed their name. Could be that they wanted to use the domain for something else initially.
- JoblessWonder 12y agoSo, today it was announced that they knew something was up as early as 12/10: "The company also confirmed Friday that it found that unauthorized data queries with similar hallmarks started as early as Dec. 10 and continued sporadically until Jan. 27. ... The hackers succeeded in penetrating the system and stealing customer data sometime after Dec. 10 and before Jan. 27, Binns said." http://www.sacbee.com/news/nation-world/national/article9480842.html#storylink=cpy http://www.sacbee.com/news/nation-world/national/article9480...
- gergles 12y agoGood job issuing the release in the middle of the night to try to avoid the PR, too. What a trainwreck. Anthem basically passed out identity theft kits, and you can even sort by income to go after the rich ones first! (Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products.)
- objclxt 12y ago> Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products. Your income is strongly correlated with your health. The lower your income the more likely you are to suffer from conditions such as obesity and diabetes, and the higher your mortality rate will be. Health insurers can use income figures as one factor when calculating the overall risk of a policy.
- FLUX-YOU 12y agoCan you lie to them about it? Do they (or any insurance) actually verify your income?
- malfist 12y agoYes, but they can use that as grounds to not pay a claim if they find out. It's not illegal, but it violates the contract you sign with them and lets them off the hook for paying for things. Mind you, they'll still keep the money you paid them.
- fiatmoney 12y ago"Why does Anthem know your income?" Possibly Affordable Care Act compliance? Calculating income-based health care subsidies appropriately?
- DsPk7ENULUUrR6R 12y ago> (Why does Anthem know your income? It doesn't seem relevant to offer you health > insurance products.) It's because they offer disability benefits, which tend to be a percentage of one's income. http://www.anthem.com/wps/portal/ahplife?content_path=life/noapplication/f4/s0/t0/pw_m010497.htm http://www.anthem.com/wps/portal/ahplife?content_path=life/n... My employer uses Anthem for health insurance but another company for disability, so if our data leaked our income data should be safe. We'll see!
- bsimpson 12y agoI know my credit card company allows me to set a password to prevent unauthorized access from someone who might have stolen this kind of data. Is there a similar system in place to make it harder for an identity thief to open accounts in my name or do other things that might damage my reputation?
- syshax 12y agoYou can freeze your credit. I don't claim it to be a comprehensive solution to a complicated topic like identity theft, but it helps, and is fairly easy and inexpensive to do. http://www.clarkhoward.com/news/clark-howard/personal-finance-credit/credit-freeze-and-thaw-guide/nFbL/ http://www.clarkhoward.com/news/clark-howard/personal-financ...
- bsimpson 12y agoI love that companies that I never agreed to have a business relationship with can charge me to preempt getting fucked by their shitty security. "Fees for Identity Theft Victims: Free; Non-victims: $10" If I wait to become a victim, I can save tens of dollars!
- briandear 12y agoI am certainly not endorsing nor do I use it personally, but Lifelock does exactly this. There are a few others as well.
- caw 12y agoLifelock doesn't catch everything though. Neil Boortz, a former syndicated radio talk show host, had someone open a bank account and take Social Security distributions for several months and Lifelock didn't catch it. http://www.wsbradio.com/weblogs/nealz-nuze/2014/sep/04/my-social-security-adventure/ http://www.wsbradio.com/weblogs/nealz-nuze/2014/sep/04/my-so...
- troymc 12y agoMy first thought upon reading this headline was, "The health insurers have an anthem??"
- kowsik 12y agoThe security industry/products seriously need a make over. So much money spent and yet, hacks just keep getting bigger and worse. [edit]: Disclaimer - I'm CTO at @menlosecurity.
- zobzu 12y agoThe security products arent great, true, but the ppl working as security engineers in companies are often quite decent. It seems to me that its the usual issue. People don't see the need for protection until they've been hit. It seems to be a cost that doesn't make sense to them. They don't even care anymore. Then they get hit hard. But it can take years.
- kowsik 12y agoTrue that about the security engineers, but they are at the mercy of products that claim to distinguish good from bad and this has never worked, IMHO. How the hell can you write signatures against malware/documents/web-sites/files/attacks/blah when there's so much diversity and quantity of stuff to keep up with? Disclaimer: I built the first IPS to be commercialized and yes we used signatures amongst other things.
- tw04 12y agoI've actually had the exact opposite experience. Security Engineers at most companies have no idea what they're doing beyond running the scanner and parroting whatever it spits out. "The scanner says your server is vulnerable" "Ya, we patched that vulnerability weeks ago" "The scanner says it's vulnerable" "OK.... looks at scanner - oh, it's just reading the banner, and not taking into account that the major rev didn't change, it's patched" "The scanner says it's vulnerable" "OK... so what if I change the banner so it doesn't pick it up as vulnerable?" "The scanner says it's secure now, thanks!!" The guys who know their stuff in security generally have a desire to actually get paid well, and have time to do legitimate research. They don't really have a desire to sit in a corporate job dealing with the mountains of bureaucratic bullshit that goes along with security in a corporation. Do you really want to be the guy who gets thrown under the bus because you had to disable strong passwords because the CEO was angry he needed both upper and lower case letters in his AD password?
- anigbrowl 12y agoAccording to the media, even their CEO's records were taken: http://www.nytimes.com/2015/02/05/business/hackers-breached-data-of-millions-insurer-says.html http://www.nytimes.com/2015/02/05/business/hackers-breached-...
- qohen 12y agoIt's mentioned in the CEO's letter on anthemfacts.com: Anthem’s own associates’ personal information – including my own – was accessed during this security breach.
- frownie 12y agoThat's very vicious PR to me. By acknowledging some guys thre were hacked too, they implicitely say that : "we're in the same boat, anthema and their customers, we'll fight together". Which, at least for me, is completely wrong. They fucekd up and they put the customers in the siht.
- ipsin 12y ago"A very sophisticated external cyber attack" which is a "security vulnerability"... The more "sophisticated" they claim this "cyber attack" is, the more I think it's a garden-variety SQL injection fuck-up. They've done a bad job of protecting their customer's data, and an even worse job of explaining what actually happened.
- kowsik 12y ago+1 on the "sophisticated" == 'SQL injection', though it's all speculation at this point.
- ipsin 12y agoThat's really my problem -- that they're leaving their victims to speculate. It's great that they "made every effort to close the security vulnerability". How's that going? They hired Mandiant to "evaluate our systems and identify solutions based on the evolving landscape." Is "evolving landscape" CEO-speak for "Oh, god, we're still leaking customer data like a sieve, make it stop!"? I'm just going to keep speculating, because if Anthem's not going to bother speaking plainly, I'm just going to assume the worst.
- jimkri 12y ago>It's great that they "made every effort to close the security vulnerability". I love that quote, they try to cover their asses by saying we closed the vulnerability. My question is why did you wait till it was taken advantage of?
- goykasi 12y agoEven better is that they didn't explicit state that they did close the vulnerability -- simply that they put forth every effort to do so.
- cmcpgh 12y agoIf we combine the Check Point firewall job posted on the Anthem Inc's website on 1/30/2015, add in the "discovery" on 1/29/2015, and think about Check Point's vulnerability to Heartbleed and Shellshock last year, one might also guess that a VPN stolen-credential compromise (like the major CHS breach last year) or a generic firewall compromise (via shellshock) are in the running as possibilities.
- beeskneecaps 12y agoI like the two Anthem job reqs that were very recently added: 2/4/15 (umm, today): http://www.careers.antheminc.com/jobs/cloud-encryption-security-professional-richmond-virginia-job-93911/ http://www.careers.antheminc.com/jobs/cloud-encryption-secur... 1/30/15: http://www.careers.antheminc.com/jobs/checkpoint-firewall-expert-atlanta-georgia-job-99975/ http://www.careers.antheminc.com/jobs/checkpoint-firewall-ex... Could be a coincidence, but I wouldn't be surprised if they were compromised several days before this press release.
- sprkyco 12y agoTo add to this a bit searching for 'security' jobs at anthem only reveals 12 jobs which to me seemed rather low.
- jdp23 12y agoPrivacy Rights Clearinghouse has a couple of excellent fact sheets on identity theft https://www.privacyrights.org/how-to-deal-security-breach https://www.privacyrights.org/how-to-deal-security-breach covers situations like this where there's been a security breach - how to order and monitory credit reports, put in a security freeze (which makes it harder to open up new credit cards or credit lines in your name), etc. https://www.privacyrights.org/content/identity-theft-what-do-if-it-happens-you https://www.privacyrights.org/content/identity-theft-what-do... covers when you've actually been the victim of an identity theft
- AtmaScout 12y agoThose are great links. Thank you very much.
- jrapdx3 12y agoIt makes me wonder. For several years the US government, Medicare, and private insurers have been pushing hard for health care providers to adopt Electronic Health Record systems. Now in the current phase "interoperability" of EHR systems is the catchword. A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it would be surprising if there were not at least some. In any case, this kind of info would probably not be made available to the public, even though it should be. Anthem's poor job of keeping confidential info private is especially distressing given the fact that many health insurers are also health care providers (e.g., hospital systems). Computer systems are very hard to operate securely, and after what happened, it's hard to trust these corporations will take the task seriously. I've been quietly predicting that security of health information is going to become the Next Big Privacy Issue as the Internet of Medical Records grows ever larger.
- kowsik 12y agoUltimately, the web is an attack vector that no one is immune to. Did you read the Syria hack recently? Just a skype chat with an attractive opposite-gender is enough to download a piece of malware masquerading as a picture you really want to see. While the human aspect has always been a key element of getting hacked, products that claim to distinguish the good vs. bad are failing big time. And this has been the pillar of enterprise security (classifying good against bad) for the last 20 years and is starting to show its age.
- roel_v 12y ago"A question to ask is how secure is a large network of EHRs going to be?" LOL, everyone 'on the inside' (by that I mean: at least anyone who works on computers, software or networks professionally) knows the answer to that question: it's going to be a train wreck. There is not a single person on this planet who really understands just 1% of the software, hardware and network infrastructure they/we work on every day; let alone how all of these interact. Computers, in 2015, are so complex, and our 'engineering' is so shoddy, that there is no way to safeguard networked data for anyone but the most determined and resourceful parties (by which I mean organizations of which there are but a handful in the whole world, and even those can't seem to keep secrets really secret.) Either way, there is no way at all that a non-IT focused organization like a healthcare insurer or provider will be able to keep data secure, and it's only a matter of time before incidents like this will become commonplace. Consider: I have an in-law who is a partner in a largish practice in my area. We talked a bit about the business aspects of the practice when she became a partner because she had to put up with all the management crap all of a sudden and it was nice for her to vent to people who had similar issues. Anyway, point being I know a bit about the finance and management of a rather typical organization like that. These people will in the next 5 years somehow get access to our, by then, country-wide EHR system. They work on computers they buy from the local computer shop because the prices 'seem reasonable' and Jimmy who works there dates the secretary or whatever; so Jimmy (whose training was in swapping out hard disks and reinstalling Windows) is the one who 'maintains' their systems, too. Their cash flow is so precarious that some months they can't pay full wages to the partners. How will an organization like that ever be able to secure their network? Their 'security' consists of the cable guy setting a non-default WPA key on their wireless router. And of course, they're required by the organization that maintains the EHR system to have 'regular auditing of their systems' to ensure security. Which consists of a couple of big 4 consultants who interview the management, tick some boxes on their checklist and make a 50-page CYA report out of that, without ever having touched a server or network. I got out of the security game 10 years ago, and it was already scary back then. Maybe somebody who still works there will feel otherwise, but computer security (on the blue team) is like FEMA sending two guys with a shovel and a Walmart plastic bucket to a dike breach. (whereas on the red team it's shooting fish in a barrel, of course.) We are truly fucked, because too few people understand the magnitude of the problem and as long as there are no problems and you don't look too closely at the robustness of things, using computers is much cheaper than the alternatives.
- danso 12y agoLooks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-data-of-millions-insurer-says.html http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out (https://news.ycombinator.com/item?id=9002003 https://news.ycombinator.com/item?id=9002003), the WHOIS points to a creation date for ANTHEMFACTS.com of `2014-12-13` with GoDaddy.
- jriordan 12y agoCould this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively: have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data And you were doxxed nearly two months ago. Or maybe not, because Anthem goes out of its way to NOT tell you when this occurred. If you were affected here's how they will notify you: We continue working to identify the members who are impacted. We will begin to mail letters to impacted members in the coming weeks. So sometime within the next month you will get a snail mail telling you that you were doxxed... and that letter will probably be extremely vague about the details, but will be quite heavy on the PR and perhaps even have a nice picture of Grandpa CEO at the top. Anthem is not taking this seriously. No matter what they are trying to communicate with their PR gloss, they seem to care about covering their asses first and really don't seem to give a hoot about all your personal data that is out there in the wild. More like AnthemLies.com...
- deleted 12y ago[deleted]
- mattmanser 12y agoThat's not what doxxing is. This is a privacy breach. Doxxing is taking an anonymous user account and turning it in to a real person. A pertinent example of doxxing is what the FBI did to linking DPR to Ross Ulbricht due to the mistake he made on a bulletin board.
- dplarson 12y agoFor those not aware, Anthem is also the insurance provider for the entire University of California system (http://www.ucop.edu/ucship/ http://www.ucop.edu/ucship/).
- bwheel 12y agoIt would be responsible of them to alert their current students and alumni of the breach, because as of now, I don't think they have. At UCB, there is a medical facility on campus and when you have ship insurance it almost feels as if your provider is the school itself. Dues are paid as part of tuition and most services can be rendered on campus, as well as, most questions about your insurance answered at their front desk. Easy to forget that you're actually a client of Anthem.
- deleted 12y ago[deleted]
- eyeareque 12y agoSophisticated attack == SQLi || "someone opened a PDF with malware" ?
- malandrew 12y agoIdentity Theft is not a thing. Others have pointed this out in the past here on HN. https://news.ycombinator.com/item?id=7369725 https://news.ycombinator.com/item?id=7369725 https://news.ycombinator.com/item?id=6583776 https://news.ycombinator.com/item?id=6583776 https://news.ycombinator.com/item?id=7369713 https://news.ycombinator.com/item?id=7369713 https://news.ycombinator.com/item?id=3482991 https://news.ycombinator.com/item?id=3482991 https://news.ycombinator.com/item?id=6583879 https://news.ycombinator.com/item?id=6583879 https://news.ycombinator.com/item?id=3483009 https://news.ycombinator.com/item?id=3483009
- Potando 12y agoMitch and Webb sketch on identity theft not being a thing https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- elwell 12y agoTurned 26 in January. Purchased Anthem medical insurance so I don't get penalized by Obamacare. Surprised how expensive it is, but bit my tongue and continue. Anthem gets hacked. My Name + SSN is probably somewhere it shouldn't be; ugh.
- thirsteh 12y agoAre you really trying to say not having health insurance is better than your info potentially being breached?
- privateman101 12y agoYou are required to give your SSN if accepting the Obamacare subsidy, look for it in the "fine print," which doesn't come close to meeting the intent of the Federal Privacy Act of 1974 (Public Law 93-579). Unfortunately, the Obamacare subsidy is a form of government assistance. The healthcare.gov operation is a joint venture between the government and non-government entities. If you are personally paying for your coverage, you "voluntarily" gave it to them when you filled out their application. I personally haven't been known to any insurance company, especially health and life, by my SSN since 1979! Remember, they can't lose (or be hacked out of) misplace, abuse or misuse what they don't have. All government agencies (but not anyone else) are required to follow the Federal Privacy Act of 1974 and it's requirements prior to you disclosing your SSN to them. Unless someone is paying you a salary, wages or interest don't give up your SSN! Don't ever give up your SSN and accept a lifetime of liability and potential ID theft for some else's 3 seconds of convenience. You are not numbered like a head of livestock. Stand your ground and take your business elsewhere when dealing with a non-government entity who insists on having your SSN! Information travels in one direction and you're not going to get it back.
- randomname2 12y agoRumours say this has ended up on torrents, any truth to that?
- kolev 12y agoSo, to stress out that they are not morons, they call this "sophisticated". You can safeguard your personal info as much as you want, but these big data warehouse will always leak it!
- imjustsaying 12y agoWhy were they storing sensitive data of former customers? It seems like a risk with no benefit, with the only justification being "all data could be valuable eventually so let's never delete even the personal sensitive data." Ironically, the data did eventually become valuable - to someone else.
- kabdib 12y agoProof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Health care in the US is . . . the phrase "utterly broken" isn't strong enough. We need a good fifteen syllable German word for how fantastically fucked up it is. Of course I'm trying to explain Anthem hanging onto data. Probably it was totally selfish ("we can send them spam") or sheer laziness.
- devicenull 12y agoDon't forget having to deal with billing nightmares even after you're no longer using an insurance company. You still could end up fighting with them over their failure to pay for something.
- logfromblammo 12y agoKreig gegen den krankenvolk.
- Estragon 12y ago> they'd say stuff like "Oh, that horrible cancer you have? > Yeah, we're not paying for it because it was a 'pre- > existing condition' that you got during that weekend you > had between two jobs six years ago." Can you give a link to an article about this? I didn't know "pre-existing condition" worked like that.
- 12y ago
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- cm2187 12y agoI can't believe it has been at least a full week since the last announcement of a massive data breach... I am concerned that if the industry doesn't fix this, regulation will.
- imjustsaying 12y agoThank you for the idea. I'm going to pass some regulation for my Wordpress sites so they'll never get hacked again.
- cm2187 12y agoThe question is not whether it will be efficient but whether it will happen. It will mean licenses and certifications to have the right to store personal data, regulations to comply with in term of system architecture with audits and penalties for breaches. More bureaucracy and processes. You won't create a website over a week end. Currently any idiot can create a database and store sensitive information without even knowing what a SQL injection or a rainbow table is. Most professions are regulated: architects, doctors, pilots, farmers, bankers, even restaurants! And each time regulations come as a result of fk ups: banks or homes collapsing, conmen selling snake oil, food poisoning, etc. IT is the only sector where mild amateurism is not only acceptable but rather the norm more than the exception.
- deleted 12y ago[deleted]
- mkopinsky 12y agoRight. Because there's no US law that covers storage of personal data by health providers. And there's no legal penalties for things like this. (Hint: http://www.ecfr.gov/cgi-bin/text-idx?SID=9e10f619aa05225aef142954e694e5a5&node=sp45.1.164.c&rgn=div6 http://www.ecfr.gov/cgi-bin/text-idx?SID=9e10f619aa05225aef1... Subpart C—Security Standards for the Protection of Electronic Protected Health Information)
- Trisell 12y agoHaving spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security as just a bunch of checkboxes on a government audit form. As long as upper management continue to see security as a cost loss center, and continue to only do the minimum nessissary to pass said audits. These breaches will continue to happen.
- FLUX-YOU 12y ago>I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I don't think we proactively pentest our stuff either. I've never heard of any security discussions but that may just mean I'm not being included. We have a few more zeroes after our PHI record count too.
- jhou2 12y agoI can't even imagine a healthcare company acceding to a proactive pentest. Even if it was compared to a vaccination or a routine health check, they still wouldn't do it. The gaping holes in security that would be uncovered. Unreal. No way in hipaa hell. lolwut, find problems that exist in our current system? Our system is fine. It's not broken, so don't break it.
- coldcode 12y agoExactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.
- pavel_lishin 12y agoTo be fair, if your systems relied on your chief architect not being hit by a bus, that would probably be worse than having the passwords stored someplace.
- feld 12y agoI'm just thrilled to recently be downgraded to an Anthem customer. I miss my old insurance.
- waspleg 12y agoThey're fantastically better than any other insurance I've had. What they cover for my family is easily another income every year. What did you have before?
- nostrademons 12y agoAnthem is very schizophrenic about their group vs. individual plans. I was covered by them under Google's group plan and they were easily the best insurance company I've had. They paid for all sorts of things that other insurers wouldn't bother for, no questions asked, and were great to deal with. Then I tried continuing with one of their individual plans after leaving, and they were easily the worst insurer I've ever dealt with. Things like not informing me that my PCP (who'd certainly been part of the group plan) was not part of the individual plan's network, or finding out that the nearest available PCP who was is 40 miles away (I live in a major metropolitan area with several million inhabitants). Not being able to change my address through the website - they have a form up that doesn't work, along with a message saying "If this form doesn't work, please call ..." Taking hours to get ahold of a human on the phone. Billing hassles. Sending out "your coverage is ending in 30 days because of non-payment" notices even though I'd faithfully paid online on-time. I'm actually quite glad that their terms are "Your policy ends automatically when you don't pay", because they've made it pretty much impossible for me to pay them - their online billpay refuses to take my payment (failing with no error message), which I suspect is because my address changed, but their website makes it impossible for me to update my address, calling them takes more time than I'm willing to invest, and I don't have any trust that if I send them a check it will actually be credited to my account. I just started a policy with Blue Cross Blue Shield instead, which has been a joy in comparison, and let Anthem lapse. If you read the Yelp reviews, they're far worse than my situation - folks being promised coverage for hospital stays and then denied coverage afterwards, and multiple lawsuits outstanding against them. The cynic in me thinks that Anthem is basically unable to continue as an operating business, and so they're triaging accounts. The big group accounts like Google get top-of-the-line service, so that they can keep them and hopefully bring in enough revenue to tide the company over. The individual accounts - anything that's small enough to (presumably) not have many other options and unable to sue - get screwed. So if you're in one of those groups, be thankful; if you're an individual, start looking elsewhere.
- AdmiralAsshat 12y agoBoy it sure does fill me with confidence to know that I am hearing about my personal information having been compromised through a news website rather than through the incompetent organization that allowed my information to be leaked in the first place...
- waspleg 12y agoWhen I woke up this morning they had sent me and my spouse an email overnight with the same letter that's posted on the anthemfacts.com site. Maybe they don't have your email address?
- ebcase 12y agoCurious if the HN community has any recommendations for identity-theft monitoring services? Each time this happens, the breached company partners with some firm or another to offer "one free year of identity monitoring" or somesuch. e.g. ProtectMyID after the Target breach. Are there better alternatives to ProtectMyID?
- jstalin 12y agoGo to any of the three credit reporting agencies and fill out the "fraud alert" form. That will place a hold on your credit report at all three credit agencies and anyone applying for credit under your name will be blocked. The entity that the person is applying for credit with has to contact you using the contact information you provide to verify that it is indeed you that's applying for credit.
- yawz 12y agoIt looks like it's sufficient to do it with one as the alert propagates to the other two. And it lasts 90 days. "Ask 1 of the 3 credit reporting companies to put a fraud alert on your credit report. They must tell the other 2 companies. An initial fraud alert can make it harder for an identity thief to open more accounts in your name. The alert lasts 90 days but you can renew it." [http://www.consumer.ftc.gov/articles/0275-place-fraud-alert http://www.consumer.ftc.gov/articles/0275-place-fraud-alert]
- Trisell 12y agoI use this. https://m.zanderins.com/identity-theft-plans https://m.zanderins.com/identity-theft-plans I have had several scares, and each time I just call them and they give me the steps to verify if it has been breached. I like the terms of their contract better as well. Just be advised that this is identity insurance. Not protection. It is designed to be reactive rather then proactive. I feel that everybody will have their identity stolen at some point, so instead of trying to prevent it. I chose to insure the consequences of it happening. I feel it's a much better return on my investment, as a lot of the protection cosines don't do much for you if they miss a theft. P.S. A million dollar reimbursement clause really helps me sleep at night.
- windexh8er 12y agoI feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back going forward as these people come of age. TL;DR If you're a parent, monitor your child's SSN for activity. Especially considering this is a healthcare breach, nobody is immune.
- babyjake 12y agoThanks for the advice. Can you give some specific steps on how to "monitor your child's SSN for activity"? How would I go about doing this?
- at-fates-hands 12y agoStart with Trans Union, they have a child specific application so you can find out if your child's SSN has been used by identity thieves: http://www.transunion.com/corporate/personal/fraudIdentityTheft/fraudPrevention/childIdTheft.page http://www.transunion.com/corporate/personal/fraudIdentityTh... If they don't have any reports, there's a good chance you're probably ok. You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/research/security-freeze/ http://consumersunion.org/research/security-freeze/ And then there's the myriad of companies who can give you protection for a monthly fee: AllClearID: https://www.allclearid.com/ https://www.allclearid.com/ LifeLock Junior: http://www.safety4yourkids.com http://www.safety4yourkids.com Also, Experian has a monitoring service as well specifically for kids: http://www.familysecure.com/ http://www.familysecure.com/ Hope this helps.
- BrokenEnso 12y agoJust filled out the Trans Union site with dummy data to check, and none of the transaction is over SSL. So, to kind out if my child's identity has been stolen I have to expose them to identity theft....
- chatmasta 12y agoEnterprise hacks are sadly becoming more common, and more sadly, it appears security is abysmal in all cases of large scale hacks. Many attacks of the past 24 months included simple exploits, social engineering or both. These are the kind of attacks a small group of rogue individuals can accomplish from computers anywhere in the world. If small groups of individual "hackers" are capable of executing high-profile operations, just imagine the capabilities of nation-state cyberwarfare forces. The intelligence agencies of large governments employ thousands of professionals, all at least as qualified as the hackers behind these attacks. The difference is that government employees (or contractors!!) have no fear of legal repercussion restraining their operational activities. When attacks like this move the market, any scrutiny of the attack must include analysis of market trading in the days following. Who profits from the drop in Anthem stock price? I imagine the SEC investigates this as part of due course, but one should consider that nation states are active investors in the stock market, whether directly or through hedge fund proxies. If a nation state can hack a large enterprise, and a nation state can trade large volumes of securities against that enterprise, then it follows that nation states can profit from cyber warfare. The next five years are going to be very interesting.
- e40 12y agoWhat's the HIPAA fine for a breach of this size? Will be be levied?
- Spoom 12y agoI'm in the process of getting Anthem to pay for my credit monitoring now. If you're in the same boat of not wanting to wait for a snail mail letter, call 1-877-263-7995 and escalate twice.
- el_benhameen 12y agoDid you have any luck with this? I spoke to a few different people and got stonewalled every time.
- Spoom 12y agoThey were supposed to call me back and didn't. I ended up just setting a 90 day fraud alert on my credit profile[1] and with ChexSystems[2]. Both are free for people who believe their identity may be compromised; you don't need a police report. They also give you a link to get a free credit report. Both may be renewed after the 90 days expires. I may still call Anthem back out of principle. 1. https://www.alerts.equifax.com/ https://www.alerts.equifax.com/ - should automatically propagate to the other two 2. https://www.consumerdebit.com/consumerinfo/us/en/chexsystems/theftaffidavit/index.htm https://www.consumerdebit.com/consumerinfo/us/en/chexsystems...
- christopheraden 12y agoI've been with Anthem since going back to the UC system. Is there any way to check if I'm affected by the breach? University of California has not made an official statement regarding the breach whatsoever. I'm looking for something similar to the way you could enter your email address and figure out if your Adobe account was hacked.
- Elrac 12y agoThis is a big company, publicly embarrassed by a breach in data security and worried about their stock price. Now they're in damage control mode. Call me a cynic, but my intuition says the whole page is a lie. My guess is the data was simply pilfered and copied to a USB stick by a disgruntled ex-employee or even a corruptible current one.
- jamra 12y agoI wonder why they needed to store SSNs online. They use SSNs to run a credit check and identity a person. Why then is it not stored encrypted and over an air gap? They can use email and phone numbers to recover passwords. This is absolutely ridiculous. They said in an email that they would pay for one year of credit protection for all those that they say were victimized. I don't think that they are capable or trustworthy enough to state who was victimized. It looks to me that they are just ignoring their responsibility for this attack. They also stated that they do not think health records have been compromised. I believe that they are just trying to avoid HIPAA fees. If so much personal data was stolen, it is likely that health information was also stolen. Generally, the patient's personally identifiable information is stored more securely than their actual health record. Now I'm off to get credit protection for me, my wife, and my one year old. Does anyone have any advice on where to begin?
- kevinchau 12y agoWhile you are waiting for Anthem to drag their feet, here's a year of AllClearID Pro on behalf of Home Depot: https://homedepot.allclearid.com/ https://homedepot.allclearid.com/
- bibabo 12y agoMost companies only focus on perimeter defense and are soft bellies once opened up or to an internal job #sonylearning And as long as it is not practice to sue companies and Cxx for negligence when they do not internally protect the data (no unencrypted data at rest) this will not change.
- Scramblejams 12y agoHow about if companies holding sensitive data were required to subject themselves to pen test attacks by properly incentivized third parties? Even if an attack were not successful the deliverables would quickly tell an experienced hand whether the attempt had been sufficiently rigorous. And that would allow for a good audit mechanism.
- JCJoverTCP 12y agoyou wouldnt happen to be a pen tester, would you?
- Scramblejams 12y agoNope. Sounds fun though.
- mparr4 12y agoI love the hero image. Nothing says "state of the art" quite like a highly pixelated image on your "we got hacked" response letter.
- criticalthinker 12y agoIf they had been using the free UAQUAS system license this attack would have never succeeded! UAQUAS not only eliminates passwords, it also examines the IP addresses that connect to a host and ensure that they are connected to an authorized program or a current web session, and if not kills the connects and blocks that IP address. Visit the uaquas.com website to learn how to protect yourself.
- criticalthinker 12y agoIf they had been using the free UAQUAS system license this attack would have never succeeded! UAQUAS not only eliminates passwords, it also examines the IP addresses that connect to a host and ensure that they are connected to an authorized program or a current web session, and if not kills the connects and blocks that IP address. Visit the uaquas.com website to learn how to protect yourself.
- siliconc0w 12y agoThis is so infuriating. Good luck trying to do anything sensible like freezing your credit. Each credit bureau competes with the next for making the process as painful as possible. 500 errors, timeouts, invalid challenge questions, ambiguous or just broken password requirements. They don't give a fuck - you're not the customer. The customer is the debt industry that pays them for your info. Oh and they each charge $10 to freeze your credit but hey you can mail them a copy of a police report and they might waive it. I gots to shell out $30 because anthem fucked up assuming I can even get their broken ass web applications to take my money.