Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

201–206 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#201

Earlier quoted context omitted.

During an auto accident & court case everyone- doctors, lawyers, insurance- used my SS# as a case identifier even though I never gave it out. If a few percent of these are sloppy, them one could be screwed. Some meth people like to dumster dive insurance companies and the like.

If you are ever unfortunate enough to be unemployed in California, and claim unemployment benefits, they print your social security number right at the top of every correspondence. Idiotic.

That's what an SSN means; it's literally what it's for. The problem is the idiots who use it as some kind of secret unique identifier for people, when it was never meant to be that.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#202

I hate the tone of that letter, has the typical PR tone all over it. Basically to sum it up: "Your Social Security Number, Name, Birthdate, Address, and everything else needed to steal your identity is at risk. But don't worry! Your credit card number is safe."

The whois[1] records for http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier. [1] http://whois.icann.org/en/lookup?name=anthemfacts.com

So, today it was announced that they knew something was up as early as 12/10:

"The company also confirmed Friday that it found that unauthorized data queries with similar hallmarks started as early as Dec. 10 and continued sporadically until Jan. 27. ... The hackers succeeded in penetrating the system and stealing customer data sometime after Dec. 10 and before Jan. 27, Binns said."

http://www.sacbee.com/news/nation-world/national/article9480...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#203
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

So, today it was announced that they knew something was up as early as 12/10:

"The company also confirmed Friday that it found that unauthorized data queries with similar hallmarks started as early as Dec. 10 and continued sporadically until Jan. 27. ... The hackers succeeded in penetrating the system and stealing customer data sometime after Dec. 10 and before Jan. 27, Binns said."

http://www.sacbee.com/news/nation-world/national/article9480...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#204
post #108

Earlier quoted context omitted.

Proof of coverage can be important. It used to be common for insurance companies to look carefully at your coverage record, and if you had any time during which you were not covered, they'd say stuff like "Oh, that horrible cancer you have? Yeah, we're not paying for it because it was a 'pre-existing condition' that you got during that weekend you had between two jobs six years ago." And the law let them do that. Hea…

> they'd say stuff like "Oh, that horrible cancer you have? > Yeah, we're not paying for it because it was a 'pre- > existing condition' that you got during that weekend you > had between two jobs six years ago." Can you give a link to an article about this? I didn't know "pre-existing condition" worked like that.

Between jobs I had my wife's insurance cover me for a weekend. The HR types I talked to made very sure that I had documentation of unbroken coverage, saying that it was pretty common for insurance companies to argue pre-existing conditions for even a day of not being under some insurance umbrella.

I believe this is no longer allowed under relatively recent law.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#205
post #142

I'm in the process of getting Anthem to pay for my credit monitoring now. If you're in the same boat of not wanting to wait for a snail mail letter, call 1-877-263-7995 and escalate twice.

Did you have any luck with this? I spoke to a few different people and got stonewalled every time.

They were supposed to call me back and didn't. I ended up just setting a 90 day fraud alert on my credit profile[1] and with ChexSystems[2]. Both are free for people who believe their identity may be compromised; you don't need a police report. They also give you a link to get a free credit report. Both may be renewed after the 90 days expires.

I may still call Anthem back out of principle.

1. https://www.alerts.equifax.com/ - should automatically propagate to the other two

2. https://www.consumerdebit.com/consumerinfo/us/en/chexsystems...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#206

Earlier quoted context omitted.

The whois[1] records for http://anthemfacts.com was registered in December. It took them months to create that PR report and prepare for damage control. They should have notified victims much earlier. [1] http://whois.icann.org/en/lookup?name=anthemfacts.com

So, today it was announced that they knew something was up as early as 12/10: "The company also confirmed Friday that it found that unauthorized data queries with similar hallmarks started as early as Dec. 10 and continued sporadically until Jan. 27. ... The hackers succeeded in penetrating the system and stealing customer data sometime after Dec. 10 and before Jan. 27, Binns said." http://www.sacbee.com/news/nation-…

No conspiracy. They were going to use it for something else.

http://webcache.googleusercontent.com/search?q=cache%3AjPUYS...

Post reply on HN