<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p>The <a href="http://krebsonsecurity.com/2015/02/china-to-blame-in-anthem-hack/">Anthem hack</a> has been getting a lot of news coverage because it is one of the larger data breaches in recent years. Of course it is in fairly good company (Sony, Home Depot, Target spring to mind) but it has some features that are unique. These features mean that the impact on those whose data was stolen is probably less than some other hacks, but that doesn't mean people can relax.</p> <!--more--> <p>All the information so far seems to indicate that the hack was undertaken by a state sponsored group (see link above and also <a href="http://krebsonsecurity.com/2015/02/anthem-breach-may-have-started-in-april-2014/">this one</a>) which means that the hackers probably aren't going to sell the details on the criminal underground for identity theft or other similar purposes. That's good, it suggests the victims won't discover that someone else has filed a tax return on their behalf to <a href="http://www.forbes.com/sites/robertwood/2015/02/12/turbotax-fraud-may-impact-federal-returns-too-fbi-investigating/">fraudulently claim a refund</a> or do some other fraud on them. Unless of course they are the target of the breach.</p> <p>Of course people who work in positions&nbsp;that may be of interest to spies (or relatives of such people) definitely DO need to be on the look out for carefully crafted spear-phish emails that convince them to open infected word documents or similar. Since the hackers have presumably got the details of many members of the same organization they will no doubt find it relatively simple to come up with a suitably plausible email from someone who seems to be a colleague.</p> <p>On the other hand that doesn't mean that the rest of the world can relax. There are already <a href="http://www.courant.com/business/connecticut-insurance/hc-anthem-phish-scam-20150206-story.html">reports</a> of scammers sending emails to anthem victims that try to trick them into&nbsp;handing over more details (though at least one of these turns out to be some good guys deliberately sending an email to try and educate) and there will no doubt be more.</p> <p>The bottom line is that everyone should treat emails from "Anthem" or any of its related names (Wellpoint, Blue Cross etc.) with extreme suspicion and should NOT click on the links. It would also, undoubtedly help to have policies that block access to IP addresses in strange places, just in case.</p></span>