Signs of China-Sponsored Hackers Seen in Anthem Attack
(Bloomberg) — Investigators of Anthem Inc.'s data breach are pursuing evidence that points to Chinese state-sponsored hackers who are stealing personal information from health-care companies for purposes other than pure profit, according to three people familiar with the probe.
Context & Ripple Effects
A day after reports that hackers took account data on as many as 80 million Anthem customers — names and identifiers, not medical records — investigators are now pursuing evidence pointing to Chinese state-sponsored actors, according to people familiar with the probe. The framing matters: this looks less like a profit-driven theft than intelligence collection against health-care companies, a category of target that holds identity data on a huge share of the US population.
The attribution claim lands in the middle of what becomes a sustained pattern: within months the same actors are tied to the OPM breach via a rare shared tool, then to United Airlines flight manifests, and later to American Airlines and Sabre. Anthem is the first domino in that sequence.
First-order effects
- Anthem's roughly 78.8 million affected customers face exposure of personal identifiers usable for fraud, while the insurer's breach response shifts from an internal security incident to a matter of state-sponsored espionage under active investigation.
- Health-care insurers join government agencies as priority targets for nation-state intrusion, forcing Anthem and its peers to treat medical-sector data as an intelligence-collection surface rather than ordinary financial-crime risk.
Second-order effects
- The same hacking campaign extends beyond health care into travel: United Airlines flight-manifest data and then American Airlines and Sabre systems are hit, pushing airlines and reservation-technology providers into defensive postures previously reserved for classified contractors.
- A shared tool between the Anthem and OPM intrusions lets investigators link separate breaches into a single campaign, raising the cost for the attackers as US agencies coordinate across what were once siloed corporate incidents.
Third-order effects
- The pattern culminates years later in a US Justice Department indictment of a China-based hacking group covering the 2015 Anthem hack among a series of intrusions — establishing that large-scale state-sponsored theft of civilian data carries named-prosecution consequences even when defendants remain beyond arrest.
- Industries holding dense personal-data troves (health insurance, government personnel, aviation) consolidate into a single threat model of state-directed collection, reshaping how regulators and boards price breach risk and disclosure obligations.
The trend: State-sponsored cyber campaigns are shifting from opportunistic profit theft to systematic collection of civilian identity and operational data across health care, government, and aviation — with US indictments becoming the long-run enforcement response.