US investigates massive data breach at health insurer

Sources say cyberattack on Anthem, the second largest US insurer, may be linked to China

The Anthem  website is displayed on a laptop computer for a photograph in Washington. Photographer: Andrew Harrer/Bloomberg

The Anthem website is displayed on a laptop computer for a photograph in Washington. Photographer: Andrew Harrer/Bloomberg

 

Several US states are investigating a massive cyberattack on US health insurer Anthem , which according to sources said is being examined for possible ties to China.

Anthem disclosed the attack late Wednesday, saying unknown hackers had penetrated a database with some 80 million records. The insurer said it suspected they had stolen information belonging to tens of millions of current and former customers as well as employees.

Attorneys general of Connecticut, Illinois, Massachusetts, Arkansas and North Carolina are looking into the breach, according to representatives of their offices and internal douments.

California’s department of insurance said it will review Anthem’s response to the data attack.

Connecticut attorney general George Jepsen asked Anthem chief executive Joseph Swedish to provide by March 4th detailed information about the cyberattack, the company’s security practices and privacy policies, according to a letter obtained by Reuters on Thursday.

“We hope and expect to work in close coordination with other attorneys general,” said Jaclyn Falkowski, a spokeswoman for Mr Jepsen. A source familiar with the probe told Reuters that a possible connection to China was being investigated, and the Wall Street Journal reported that people close to the investigation say some tools and techniques used against Anthem were similar to ones used in previous attacks linked to China.

The origin of cyber attacks is difficult to determine, China’s foreign ministry spokesman, Hong Lei, said on Friday. “Such careless identification of the relevant attacker clearly is unreasonable,” Hong told a news briefing in Beijing. Late on Wednesday, the FBI said it was looking into the matter but did not discuss suspects. “As far as China being involved, I don’t know,” said FBI spokesman Paul Bresson.

“I don’t think we know yet. Our investigation is ongoing.” On Friday, Anthem officials are scheduled to brief the House Energy and Commerce Committee on the breach. “This latest intrusion into patients’ personal information underscores the increasing magnitude and evolving nature of cyber crimes,” Fred Upton, the committee’s chairman, said in a statement. “Every business is at risk and American consumers are anxious.”

President Barack Obama’s cybersecurity adviser, Michael Daniel, speaking at a seminar in Washington, called the data breach “quite concerning” and warned consumers to change their passwords and monitor their credit scores.

Reuters