International
Data on 80mn stolen in latest security breach
Data on 80mn stolen in latest security breach
AFP/Reuters/New YorkHackers stole data on as many as 80mn customers at US health insurance giant Anthem, in what is believed to be the worst breach on record of medical records.“Cyber attackers executed a very sophisticated attack to gain unauthorised access to one of Anthem’s IT systems and have obtained personal information relating to consumers and Anthem employees who are currently covered, or who have received coverage in the past,” a statement on Wednesday from the second-largest US health insurer said.“Once the attack was discovered, Anthem immediately made every effort to close the security vulnerability, contacted the FBI and began fully co-operating with their investigation,” said chief executive Joseph Swedish. “Anthem’s own associates’ personal information – including my own – was accessed during this security breach. We join you in your concern and frustration, and I assure you that we are working around the clock to do everything we can to further secure your data.”The information includes names, birth dates, social security numbers, street addresses, e-mail addresses and employment information, the company said.“The affected database has records for 80mn people and tens of millions” of them were stolen, spokeswoman Cindy Wakefield said.The breach is the latest exposing personal information on millions.Last year, US retailer Home Depot said 53mn e-mail addresses were stolen, months after fellow retailer Target said personal data on 70mn customers was accessed.Some experts say medical data can be even more lucrative to hackers than credit cards, because they can create fake identities for prescription drugs to be resold, or file false insurance claims.Security experts welcomed Anthem’s decision to make the issue public swiftly.“I’m pleased to see Anthem publishing information about the security breach online, and I’m sure customers will be grateful that the company has not tried to hide away the news,” independent security researcher Graham Cluley said in a blog post. “But what’s really necessary is for companies and organisations to do a better job at protecting our personal information. Too many firms who are entrusted with data from the general public are finding themselves in the uncomfortable position of admitting that they have been hacked.”Meanwhile, President Barack Obama’s cybersecurity adviser said yesterday that he was concerned about a data breach at Anthem.“Obviously it’s quite concerning that we would have yet another intrusion of this size,” Michael Daniel said at a seminar organised by Bloomberg Government.“It’s particularly disturbing especially when it hits that many people,” Daniel said, advising affected consumers to change their passwords and monitor their credit scores.He declined to comment further on the breach, which is under investigation by the Federal Bureau of Investigations.