Anthem says breach may have also affected up to 18.8M Blue Cross Blue Shield customers
Anthem says at least 8.8 million non-customers could be victims in data hack — (Reuters) - Health insurer Anthem Inc, which earlier this month reported that it was hit by a massive cyberbreach …
Context & Ripple Effects
Three weeks after Anthem disclosed hackers took account information on as many as 80 million customers, the scope keeps widening: the insurer now says the same intrusion may also have swept in up to 18.8 million Blue Cross Blue Shield members and at least 8.8 million non-customers. Attribution reporting pointing to China-sponsored activity and Symantec's finding that Anthem was a secondary target for the Black Vine group frame this as espionage-adjacent rather than ordinary financial theft.
The blast radius extends across the Blue Cross system itself — weeks later, Premera Blue Cross disclosed its own sophisticated hack affecting up to 11 million people, and Excellus Blue Cross Blue Shield separately revealed a 2013 breach exposing over 10 million records. The pattern culminated in Anthem's eventual agreement to pay $115 million to settle the class action, one of the largest data-breach payouts on record.
First-order effects
- Up to 27.6 million additional individuals — 18.8 million Blue Cross Blue Shield members plus at least 8.8 million non-customers — join the notification and credit-monitoring obligations from the original 80-million-customer disclosure, expanding Anthem's direct remediation costs.
Second-order effects
- Blue Cross Blue Shield licensees like Premera face heightened scrutiny of their own security postures; Premera's subsequent disclosure of a January hack affecting up to 11 million people shows the attackers were working the federation, not just Anthem.
Third-order effects
- With Excellus's 2013 breach also surfacing, health insurers are revealed as systematically under-defended against nation-state-grade intrusion, pushing the industry toward breach-class litigation and regulatory pressure that treats member-data exposure as an enterprise-wide liability rather than a per-insurer incident.
The trend: Health insurers are consolidating into a single class of high-value espionage targets whose breaches compound across the Blue Cross federation and end in landmark settlements.