BreachExchange mailing list archives

Deloitte hack hit server containing emails from across US government


From: Richard Forno <rforno () infowarrior org>
Date: Tue, 10 Oct 2017 07:42:44 -0400

Deloitte hack hit server containing emails from across US government
Nick Hopkins
Tuesday 10 October 2017 07.00 EDT Last modified on Tuesday 10 October 2017 07.02 EDT

The hack into the accountancy giant Deloitte compromised a server that contained the emails of an estimated 350 
clients, including four US government departments, the United Nations and some of the world’s biggest multinationals, 
the Guardian has been told.

Sources with knowledge of the hack say the incident was potentially more widespread than Deloitte has been prepared to 
acknowledge and that the company cannot be 100% sure what was taken.

Deloitte said it believed the hack had only “impacted” six clients, and that it was confident it knew where the hackers 
had been. It said it believed the attack on its systems, which began a year ago, was now over.

However, sources who have spoken to the Guardian, on condition of anonymity, say the company red-flagged, and has been 
reviewing, a cache of emails and attachments that may have been compromised from a host of other entities.

The Guardian has established that a host of clients had material that was made vulnerable by the hack, including:

• The US departments of state, energy, homeland security and defence.

• The US Postal Service.

• The National Institutes of Health.

• “Fannie Mae” and “Freddie Mac”, the housing giants that fund and guarantee mortgages in the US.

Football’s world governing body, Fifa, had emails in the server that was breached, along with four global banks, three 
airlines, two multinational car manufacturers, energy giants and big pharmaceutical companies.

The Guardian has been given the names of more than 30 blue-chip businesses whose data was vulnerable to attack, with 
sources saying the list “is far from exhaustive”.

Deloitte did not deny any of these clients had information in the system that was the target of the hack, but it said 
none of the companies or government departments had been “impacted”. It said “the number of email messages targeted by 
the attacker was a small fraction of those stored on the platform”.

This assurance has been contested by sources that spoke to the Guardian. They said Deloitte’s public position belied 
concern within the company about exactly what had happened and why.

< - >

https://www.theguardian.com/business/2017/oct/10/deloitte-hack-hit-server-containing-emails-from-across-us-government
_______________________________________________
BreachExchange mailing list sponsored by Risk Based Security
BreachExchange () lists riskbasedsecurity com

If you wish to Edit your membership or Unsubscribe you can do so at the following link:
https://lists.riskbasedsecurity.com/listinfo/breachexchange

Current thread: