Symantec: Anthem was a secondary target for hacking group Black Vine, which primarily targeted aerospace, energy, military, and technology industries
Group that hacked Anthem shared weaponized 0-days with rival attackers — History's biggest healthcare breach was just another hack for Black Vine gang.
Context & Ripple Effects
Six months after hackers pulled account records on as many as 80M Anthem customers — a figure that grew when up to 18.8M Blue Cross Blue Shield members were added — Symantec is recasting the breach as one operation inside a broader campaign. Its earlier reporting had already pointed toward China-sponsored actors behind the Anthem attack; this analysis names the group Black Vine and demotes Anthem to a secondary target.
The reframe matters because Black Vine's primary focus was aerospace, energy, military, and technology firms — meaning a health insurer holding some of the most sensitive consumer data on file was collateral, not the objective.
First-order effects
- Health insurers like Anthem now know their breach came from a group whose real quarry sat elsewhere, forcing security budgets built for fraud prevention to be rebuilt around espionage-grade intrusion.
- Black Vine's practice of passing weaponized zero-days to rival attackers means exploits developed for its campaigns keep working after the group moves on.
Second-order effects
- Aerospace, energy, and defense contractors named as Black Vine's primary targets face pressure to treat themselves as already-in-campaign rather than at-risk, reshaping procurement for network defenses.
- Zero-day sharing erodes the scarcity value that made top-tier exploits expensive, lowering the entry cost for less capable crews attacking the same victims.
Third-order effects
- The pattern held after Black Vine: Symantec later tracked the Dragonfly group inside US and European power-grid operators' operational networks (2017) and Orangeworm striking X-ray and MRI equipment in healthcare (2018) — state-linked groups running multi-sector campaigns where any breached dataset gets used.
- If espionage groups keep treating commercial networks as interchangeable targets, sector-by-sector compliance regimes give way to threat-actor-based defense, with attribution firms like Symantec becoming de facto infrastructure for corporate security planning.
The trend: State-sponsored hacking groups are running multi-industry campaigns that treat individual breaches as opportunistic byproducts, collapsing the line between espionage targets and everyone else.