8 ms·
Officials at Anthem detected the theft of the trove of customer information as it was being sent from its computers on Jan. 29, according to one of the people,
by dev1n 12y ago
Officials at Anthem detected the theft of the trove of customer information as it was being sent from its computers on Jan. 29, according to one of the people, which they said is still in its early stages.
As others have pointed out, running a whois on the anthemfacts webpage returns a registration date of 12/13/2014 [1] which is most likely when the breach occurred. Not January 29th.
[1]: http://whois.domaintools.com/anthemfacts.com http://whois.domaintools.com/anthemfacts.com
- bbanyc 12y agoThe domain doesn't prove they knew anything then. It's too generic, it's not like it was something like anthemdatabreachfacts.com. The company just changed its name from Wellpoint to Anthem in December and could have bought up a bunch of "anthem*.com" domain names around then to keep in reserve.
- dmschulman 12y agoOr they bought the domain back then and planned to use it for this explicit purpose. It's not a question of "will" a big company get hacked, it's a question of "when". Also I'm sure a major healthcare company that handles tens of millions of sensitive personal records has enough foresight to see a data breach coming. HIPAA and ACA probably mandate healthcare companies having this exact kind of plan ready to deploy in the event of a hack.
- yebyen 12y agoCome on, give them some credit for the facts they did provide. They detected a breach where sensitive data was stolen on January 29th. This does not preclude that they also detected a breach first, on or before December 13! Did anyone record any downtime of their public-facing systems in this time? You know when you're a sysadmin and you notice something really bad happening, you shut down the affected systems immediately and try to minimize the damage? You never know what kind of back doors have been put in place, after you are breached. It is also entirely plausible that the breach is still ongoing now, after a month and a half why not, but they are just no longer able to detect it. These people are some of the most important cogs in the health care machine, the insurance providers! If they had some kind of downtime that was actually affecting their ability to provide services, well then they might actually be subject to some real form of legal action, maybe even pay serious damages to their customers. Thank heavens that didn't happen! They are paying lip service to security because it's not as important to them as, you know, basically anything else. Like say, receivables. It's only identity theft!
- yebyen 12y agoRelevant: https://news.ycombinator.com/item?id=9012996 https://news.ycombinator.com/item?id=9012996 "The company also confirmed Friday that it found that unauthorized data queries with similar hallmarks started as early as Dec. 10 and continued sporadically until Jan. 27."