On 4 February 2015 America's second-largest health insurer, Anthem, said criminals had broken into its servers and taken personal information on current and former members and employees: names, dates of birth, member identification and Social Security numbers, street and email addresses, and employment details including income. No medical records and no credit-card or bank data had been taken, the company said, and it never had to withdraw that. It called the incident a "very sophisticated external cyber attack" and gave no number that day. Reporting that week put the total at as many as 80 million; on 24 February the company settled on 78.8 million people. The notice ran from Anthem Blue Cross to Empire, Amerigroup and Unicare — the map of a business called WellPoint until the previous December.

The discovery was eight days old. On 27 January a database administrator noticed his own credentials being used to run a query he had not initiated; the alarm went up, and on 29 January Anthem told federal authorities and the health industry's threat-sharing body that its inquiry had found a breach rather than a fault. The Associated Press reported that five technology employees' credentials had been compromised. Three dates matter, and are usually collapsed into one. The intrusion: a later examination by state insurance commissioners dated it to 18 February 2014. The theft: contemporary reconstruction placed the emptying of the data warehouse at 10 December 2014. The disclosure: 4 February 2015. Roughly a year inside, seven weeks between the query and the alarm, eight days between the alarm and the public.

Attribution ran ahead of confirmation. Within two days investigators were reported to suspect Chinese state-sponsored hackers; Anthem said nothing about who. On 9 February research by the firm ThreatConnect, first reported by Brian Krebs, showed the preparation: we11point[dot]com — the old name, two digits for two letters — registered on 21 April 2014 to a bulk domain service in China, its record scrubbed of any Chinese connection eight minutes later, with subdomains posing as the company's own portals, and malware signed with a DTOPTOOLZ Co. certificate. Four vendors had already given one China-linked cluster four names: Deep Panda at CrowdStrike, Axiom at Novetta, Group 72 at Cisco, Shell_Crew at RSA. That is infrastructure and inference, not a flag. By 7 February Anthem was telling callers that the credit-monitoring emails and calls were not its own, and that it would write by post.

The endings took years. The examination by state insurance commissioners concluded that the company had taken reasonable measures before the breach and that its remediation worked; it also found, without naming a country, that the intrusion had probably been ordered by a foreign government. In 2017 Anthem agreed to pay $115 million to settle the class actions, the largest data-breach settlement to that date; in October 2018 it paid the federal health-privacy regulator $16 million, the largest that office had reached. In May 2019 two Chinese nationals were indicted over the breach; no trial has been reported. Where the files went was never established in public: they were expected on the criminal market, and no public account has placed them there — an absence that is itself the espionage reading.

Also that month · 16 February

Two reports, one day

Kaspersky Lab published twice on 16 February. The first named Carbanak, a gang that entered banks through phishing attachments, watched their staff for two to four months, then cashed out by inflating balances, moving money by transfer, or making cash machines pay a waiting mule. The researchers counted up to 100 financial institutions, put the loss at $2.5 million to $10 million a bank, and said the total could be as high as $1 billion. The figure was an estimate, contested at once: Fox-IT and Group-IB had described the same crew in December 2014 as Anunak with far smaller losses, Fox-IT confirming the two names were one group; Brian Krebs called the billion generous; and the FBI, the Secret Service and US banking groups reported no American banks affected. The second described the Equation Group, active since at least 2001: modules that rewrote hard-drive firmware from more than a dozen makers, a worm called Fanny carrying two zero-days that reached Stuxnet only later, and conference CD-ROMs posted to scientists after a Houston meeting. About 500 infections were counted in 42 countries, probably a fraction. Kaspersky did not name the NSA.

Also that month · 13–27 February

The keys were already copied

On 13 February, at Stanford, the President signed Executive Order 13691, telling Homeland Security to foster information-sharing organisations. Six days later The Intercept showed the other side. From Snowden documents it reported that a joint GCHQ and NSA unit formed in April 2010, the Mobile Handset Exploitation Team, had gone after Gemalto, which makes some two billion SIM cards a year — reading staff and telecom employees' private mail to find who handled keys; one two-week operation against six email addresses was recorded as yielding 85,000 keys. Gemalto answered on 25 February: it had detected attacks in 2010 and 2011; there were reasonable grounds to believe an NSA and GCHQ operation probably happened; only its office networks were reached; and no mass theft of keys had occurred — a conclusion framed around 3G and 4G. The month closed smaller: on 20 February Homeland Security told Lenovo laptop owners to remove Superfish and its self-signed root certificate — the Digital Guard desk's story; and on 27 February Uber disclosed a database of about 50,000 drivers' names and licence numbers, reached on 13 May 2014 and found on 17 September.

India desk · February 2015

On both maps, unconsulted

India appears twice in February 2015's documents, both times as a place things were done to rather than a party told about them. The GCHQ page of May 2011 that The Intercept published on 19 February listed Gemalto facilities in more than a dozen countries, India among them. Kaspersky's Equation Group research of 16 February, which counted about 500 infections in 42 countries, reportedly found India among the implanted countries, alongside Iran, Russia, Pakistan, Afghanistan, China, Syria and Mali. No Indian institution was named in either. Gemalto's reassurance of 25 February was pitched at 3G and 4G, the generations The Intercept called more secure; the older 2G standard, whose encryption the same article described as deeply flawed, was still the ordinary way an Indian handset reached the world's second-largest telephone network.

What India had that month was machinery for counting rather than for telling. CERT-In had existed since January 2004, and the 2008 amendment to the Information Technology Act had named it the national incident-response agency under section 70B; it gathered incident reports; the National Cyber Coordination Centre, given approval in principle in May 2013, was still unbuilt — of roughly ₹1,000 crore allocated to cyber security in November 2014, about ₹800 crore was earmarked for it, and a minister told Parliament only in August 2017 that its first phase was operational. Nothing in Indian law that February obliged a company to tell its customers what Anthem had told its members on the fourth. That obligation arrived in pieces and much later: CERT-In's directions of 28 April 2022, with their six-hour clock, and the Digital Personal Data Protection Act of 2023. February 2015's Indian security story is one this desk could not date, and will not invent.

AI Tech desk · February 2015

Forty-nine games from raw pixels

Nature's issue of 26 February 2015 carried "Human-level control through deep reinforcement learning" from Google DeepMind, which Google had bought thirteen months earlier. The deep Q-network described in it was given only the screen pixels and the running score, kept one architecture and one set of hyperparameters throughout, and across 49 Atari 2600 games outperformed competing methods on almost all of them while matching or bettering a professional human games tester. A 2013 workshop paper from the same group had handled seven games and beaten a human expert on three. Earlier that month, on 10 February, Microsoft Research reported that a parametric rectified linear unit and a new initialisation scheme had brought its ImageNet classification error to 4.94 per cent against a 5.1 per cent human benchmark — while cautioning that this did not mean machine vision had overtaken human vision in general. Its residual networks won the competition outright before the year ended; DeepMind's next system beat a professional Go player that October, in secret until the following January.

Digital Guard desk · February 2015

Superfish, and a password called komodia

On 19 February 2015 it emerged that Lenovo consumer notebooks shipped since September 2014 carried Superfish VisualDiscovery, adware that injected shopping results into pages by installing its own root certificate and intercepting HTTPS. The certificate was the same on every machine, and Robert Graham of Errata Security recovered its private key in hours; the passphrase was komodia, the name of the Israeli firm whose interception library Superfish used. Anyone on the same network could impersonate any site silently. Lenovo said at first that it saw no evidence substantiating the security concerns; by 20 February it had published removal instructions and a tool, Homeland Security had issued an advisory, and Microsoft, McAfee and Symantec were removing the software and its certificate automatically. Its chief technology officer wrote on 23 February that Lenovo had "messed up badly". Days later Hanno Böck found PrivDog, an ad-replacement tool endorsed by Comodo's chief executive, accepting invalid certificates outright; Comodo called the issue minor and said it had not distributed those versions. In September 2017 Lenovo settled with the Federal Trade Commission and 32 states.

⏳ Time capsule — February 2015

  • On 10 February the Aam Aadmi Party was declared the winner of 67 of Delhi's 70 assembly seats, polled three days earlier, leaving the BJP three and the Congress none; Arvind Kejriwal took oath as chief minister at Ramlila Maidan on 14 February.
  • On 15 February India beat Pakistan by 76 runs at the Adelaide Oval — 300 for seven against 224 — in a Cricket World Cup that had opened the day before in Australia and New Zealand, and which Australia won in Melbourne on 29 March.
  • On 22 February Birdman took best picture at the 87th Academy Awards at the Dolby Theatre, one of four awards for the film on a night hosted by Neil Patrick Harris; every one of the eight nominated pictures won something, the first time that had happened since the Best Picture field was expanded at the 82nd ceremony in 2010.
  • Leonard Nimoy died on 27 February at his home in Bel Air, Los Angeles, aged 83, of complications of chronic obstructive pulmonary disease; his last message on Twitter, posted four days earlier on 23 February, signed off with the initials of his character's farewell.
Where it stands today — 2026

The census, and the toolkit

A decade on, February 2015 reads as the month it became plain that ordinary personal records are collected by states as well as sold by criminals. Anthem's careful line — no medical files, no card numbers — held, and mattered less than it sounded, because the identity file was the point. Four months later the US Office of Personnel Management disclosed intrusions of its own (June 2015): 4.2 million personnel files announced in June, then 21.5 million people in July as the security-clearance questionnaires themselves were counted, and 5.6 million sets of fingerprints by September. Washington never formally attributed it: officials named China only in anonymous briefings, and the one arrest — a Chinese national held at Los Angeles airport in August 2017 — was a conspiracy charge over supplying the Sakula malware researchers had tied to both OPM and Anthem, not a charge for either intrusion. Health data never came off the list. By February 2024 the danger to it was extortion rather than espionage, and the damage was measured in unpaid hospitals.

The two reports of 16 February aged differently. Carbanak's billion was never confirmed, and the case ended in a Spanish arrest instead: Europol said on 26 March 2018 that it had detained the alleged mastermind in Alicante (March 2018). The Equation research needed no such qualification. In August 2016 a group calling itself the Shadow Brokers put that toolkit up for sale, and in May 2017 one exploit from it carried WannaCry into hospital networks. Gemalto's inquiry settled nothing about who ultimately holds the root of a mobile network, a question still open in 2026. And the alarm that began the month's largest story was not a product or a platform. It was one administrator who looked at a running query and knew he had not written it.