4 ms·
They have evidence of an attack going back to Dec 10, a Wednesday. "Anthemfacts.com" was registered on Dec 13th which was, assuming US rather than GMT, the fol
by sandworm 12y ago
They have evidence of an attack going back to Dec 10, a Wednesday.
"Anthemfacts.com" was registered on Dec 13th which was, assuming US rather than GMT, the following friday.
The proximity and order of those dates cannot be coincidence. It would seem someone at Anthem was confident enough to start prepping the PR campaign almost TWO MONTHS before the public, or the Conn AG, was notified. And during tax season!
- recursive 12y ago"cannot" be a coincidence. It absolutely can be. There are only so many dates.
- SyneRyder 12y agoWhile it could be coincidence, I think you're onto something. If the attack was first discovered on Dec 10, that means Anthem notified the public on Day 59 (February 6 is the timestamp at the bottom of AnthemFacts.com). That is the last possible chance they have to legally notify the public. The Wall Street Journal[1] notes that: "Federal law requires health-care companies to inform consumers and regulators when they suffer a data breach involving personally identifiable information, but they have as many as 60 days after the discovery of an attack to report it." Day 59 is cutting it awfully close. [1] http://www.wsj.com/articles/health-insurer-anthem-hit-by-hackers-1423103720 http://www.wsj.com/articles/health-insurer-anthem-hit-by-hac...
- yclept 12y agoFeb 6 would be the last legal work day
- _nickwhite 12y agoYour conclusion isn't exactly the truth. According to Anthem, they used that site to host other information prior to the breach. Via Twitter @Antheminc: "Previously, http://AnthemFacts.com http://AnthemFacts.com hosted information about our mental health coverage: http://ow.ly/IzcZr" http://ow.ly/IzcZr"
- sandworm 12y agoThat is IF we assume Anthem's statement are "the truth". I don't make that assumption. In fact in these situations I assume every statement from such a corporation may or may not be true. Without backup from external sources, the corporate twitter account is no more trustworthy than any other self-serving media release. The fact that they filled the website with mental heath data does not detract from the theory that they had knowledge of the breech months ago. It only adds to the theory that they were trying to keep things quiet for as long as legally possible.