Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

61–70 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#61
post #59

Earlier quoted context omitted.

You seem to be implying that the domain was registered in response to the breach. Could it be that the anthemfacts.com domain was intended for a different use, or to prevent someone else from registering it, and was re-purposed after the intrusion to present Anthem's case? I don't know much about SEO, but quarantining negative information on a separate, immediately available domain might be the motivation here.

A domain name that is being used exclusively to address to data breach, and was registered within the past 2 months. And it's just a coincidence? Seems very unlikely. And I'm sure they're quarantining negative info on an unrelated domain, but why would they even need to consider repurposing an existing domain name, instead of buying one? We're not talking about somebody doing a side project and hoping to save a few b…

"A domain name that is being used exclusively to address to data breach..."

My point is that while it is used for that purpose now, that doesn't mean that it was registered for that purpose back in mid-December. Your theory about the breach occurring earlier and being concealed until now is certainly possible, but the domain registration date on its own is not supporting evidence.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#62
post #37

High five to all the CISAs, CISMs, CGEITs, CRISCs and CISSPs at Anthem.

Makes you wonder doesn't it, the dollars that got spent to have something blatant happen. Its not an industry I'd like to be in, with everything so compromised.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#63
Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after.

Yet companies I work with now big and small look at security as just a bunch of checkboxes on a government audit form. As long as upper management continue to see security as a cost loss center, and continue to only do the minimum nessissary to pass said audits. These breaches will continue to happen.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#64
post #18

Privacy Rights Clearinghouse has a couple of excellent fact sheets on identity theft https://www.privacyrights.org/how-to-deal-security-breach covers situations like this where there's been a security breach - how to order and monitory credit reports, put in a security freeze (which makes it harder to open up new credit cards or credit lines in your name), etc. https://www.privacyrights.org/content/identity-theft-wha…

Those are great links. Thank you very much.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#65
post #56

I can't believe it has been at least a full week since the last announcement of a massive data breach... I am concerned that if the industry doesn't fix this, regulation will.

Thank you for the idea. I'm going to pass some regulation for my Wordpress sites so they'll never get hacked again.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#66
post #4

I know my credit card company allows me to set a password to prevent unauthorized access from someone who might have stolen this kind of data. Is there a similar system in place to make it harder for an identity thief to open accounts in my name or do other things that might damage my reputation?

I am certainly not endorsing nor do I use it personally, but Lifelock does exactly this. There are a few others as well.

Lifelock doesn't catch everything though. Neil Boortz, a former syndicated radio talk show host, had someone open a bank account and take Social Security distributions for several months and Lifelock didn't catch it. http://www.wsbradio.com/weblogs/nealz-nuze/2014/sep/04/my-so...

Re: “Anthem was the target of a very sophisticated external cyber attack”

#67
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

>I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes."

I don't think we proactively pentest our stuff either. I've never heard of any security discussions but that may just mean I'm not being included. We have a few more zeroes after our PHI record count too.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#68
post #9
post #3

Good job issuing the release in the middle of the night to try to avoid the PR, too. What a trainwreck. Anthem basically passed out identity theft kits, and you can even sort by income to go after the rich ones first! (Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products.)

> Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products. Your income is strongly correlated with your health. The lower your income the more likely you are to suffer from conditions such as obesity and diabetes, and the higher your mortality rate will be. Health insurers can use income figures as one factor when calculating the overall risk of a policy.

Can you lie to them about it? Do they (or any insurance) actually verify your income?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#69
post #59

Earlier quoted context omitted.

You seem to be implying that the domain was registered in response to the breach. Could it be that the anthemfacts.com domain was intended for a different use, or to prevent someone else from registering it, and was re-purposed after the intrusion to present Anthem's case? I don't know much about SEO, but quarantining negative information on a separate, immediately available domain might be the motivation here.

A domain name that is being used exclusively to address to data breach, and was registered within the past 2 months. And it's just a coincidence? Seems very unlikely. And I'm sure they're quarantining negative info on an unrelated domain, but why would they even need to consider repurposing an existing domain name, instead of buying one? We're not talking about somebody doing a side project and hoping to save a few b…

It's a generic domain related to their brand. I'm sure they have thousands of domains.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#70
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Exactly my experience. We had all the production passwords for servers and databases in a text file in the repository because the chief architect didn't like to remember passwords. When I pointed this out as a HIPAA violation the CTO told me they passed their audits so it didn't matter.
Post reply on HN