Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

71–80 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#72
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

>I worked for a small medical company that had access to 20,000 PHI records

I can only imagine the data protection standards at small equipment manufacturers and old-school pharmacies. I'd guess their biggest security measure is keeping paper files in a locked office.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#73
post #58
post #55

Earlier quoted context omitted.

Dox -> documents -> publishing personal information, no? Why does the victim have to be anonymous?

In modern usage of the term they don't. The term originated in underground circles where anonymity by all participants was assumed, and where there were probably legal or criminal revenge consequences for tying a pseudonym to a real identity. Kind of like how troll now means 'person who is an asshole on the internet' instead of 'post designed to rile up and elicit frivolous responses'. The meaning has changed over ti…

I don't know, even Wikipedia seems to agree with me.

http://en.wikipedia.org/wiki/Doxing

And didn't the GGers "dox" Randi, Anita, Brianna, etc?

But I'm even more old school because I'd just call it skiptracing instead of doxing....

Re: “Anthem was the target of a very sophisticated external cyber attack”

#74
post #31

Greeeeeeeeat. Anthem just became my health care provider. This fills me with confidence. I'm especially unimpressed by Anthem's failure to hire a good copy editor for such a vital message, as evidenced by the painfully obvious error at the end of the penultimate paragraph: "share that information you" should read "share that information with you".

My new health care provider as of January 1st!

Re: “Anthem was the target of a very sophisticated external cyber attack”

#75
post #59

Earlier quoted context omitted.

A domain name that is being used exclusively to address to data breach, and was registered within the past 2 months. And it's just a coincidence? Seems very unlikely. And I'm sure they're quarantining negative info on an unrelated domain, but why would they even need to consider repurposing an existing domain name, instead of buying one? We're not talking about somebody doing a side project and hoping to save a few b…

What's unlikely about it? Maybe if the domain name was "anthemdatabreachinfo.com" or something more specific, but "anthemfacts.com"? Many companies register lots of variation of domain names that they aren't using. I don't think it's unlikely at all that this came up, and there was a meeting where they said "OK, do we have any existing domain names we can use for this?"

So what have they been using the domain for in the few weeks since registration? The domain doesn't appear in web.archive.org until today, and searching Google for the domain between December and the end of January shows nothing.

The website itself says "we have created a dedicated website ... anthemfacts.com" for this incident.

[Edit: replaced two egregious uses of "website" with "domain"]

Re: “Anthem was the target of a very sophisticated external cyber attack”

#76
post #47

Earlier quoted context omitted.

Who cares about credit card numbers when you are protected for free and your credit card can be reissued unlike your SSN. I can't believe than in 2015 there's no modern way to verify and protect your identity! There are still so many stupid system relying on your last 4 of your SSN or DoB as authentication!

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

There have been some attempts at a National ID, but it keeps getting shot down because people believe it's the Mark of the Beast.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#77
post #73
post #58

Earlier quoted context omitted.

In modern usage of the term they don't. The term originated in underground circles where anonymity by all participants was assumed, and where there were probably legal or criminal revenge consequences for tying a pseudonym to a real identity. Kind of like how troll now means 'person who is an asshole on the internet' instead of 'post designed to rile up and elicit frivolous responses'. The meaning has changed over ti…

I don't know, even Wikipedia seems to agree with me. http://en.wikipedia.org/wiki/Doxing And didn't the GGers "dox" Randi, Anita, Brianna, etc? But I'm even more old school because I'd just call it skiptracing instead of doxing....

You're ignoring the bits of that article you don't like:

Essentially, doxing is revealing and releasing records of an individual, which were previously private, to the public.

Where's the "reveal" in this hack? They'll use the hacked info privately or sell it.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#78
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

Could this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively: have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data And you were doxxed nearly two m…

The domain could have been created as part of a crisis preparedness plan. I know a lot of boards were scrambling to beef up their incident response plans after the Target and Home Depot incidents.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#79
post #9

Earlier quoted context omitted.

> Why does Anthem know your income? It doesn't seem relevant to offer you health insurance products. Your income is strongly correlated with your health. The lower your income the more likely you are to suffer from conditions such as obesity and diabetes, and the higher your mortality rate will be. Health insurers can use income figures as one factor when calculating the overall risk of a policy.

Can you lie to them about it? Do they (or any insurance) actually verify your income?

Yes, but they can use that as grounds to not pay a claim if they find out.

It's not illegal, but it violates the contract you sign with them and lets them off the hook for paying for things. Mind you, they'll still keep the money you paid them.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#80
post #21

Looks like they misled the New York Times: http://www.nytimes.com/2015/02/05/business/hackers-breached-... > Anthem learned of the hacking last week and called in Mandiant over the weekend. The company was not obligated to report the breach for at least several more weeks but chose to do so now to show that it was treating the matter seriously. As user jakejohns has pointed out ( https://news.ycombinator.com/item?id=…

Could this be any more patronizing and offensive? Look, if you are Anthem member, or if you were an Anthem member, you've been doxxed... and quite comprehensively: have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data And you were doxxed nearly two m…

This is really frightening. Honestly, what are these people supposed to do now? I'm not even really sure how to vet insurance companies' data privacy, since most get their insurance through their employer.
Post reply on HN