Attacks/Breaches

9/25/2017
03:50 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Breach at Deloitte Exposes Emails, Client Data

Intrusion may have resulted from company's failure to properly secure a key administrator account.

Big Four accounting giant and cybersecurity consultancy Deloitte has suffered a data breach that ironically enough may have resulted from the firm's failure to follow its own security advice to clients.

The Guardian on Monday reported that an intrusion at Deloitte between October and November last year exposed emails containing highly sensitive data belonging to an unknown number of large US companies and government organizations.

The intrusion, which Deloitte did not discover until March 2017, apparently stemmed from the company's failure to use two-factor authentication to protect a critical administrator account — something that it advocates as a best practice for clients. Attackers used the account to get privileged and unrestricted access to Deloitte's entire Azure-hosted email system.

During the multiple months that the threat actors managed to remain undetected on Deloitte's network, they potentially had access to some 5 million emails. The attackers also had potential access to usernames, passwords, health information, and highly sensitive data belonging to an unspecified number of Deloitte's clients, The Guardian said.

Deloitte itself has claimed that the actual number of emails and the scope of the data that was affected is only a "fraction" of the number suggested by The Guardian.

In an emailed statement to Dark Reading, Deloitte confirmed the breach and said the attackers had accessed data from the company's email platform. Deloitte's investigation of the incident has enabled it to understand precisely what data was at risk and what the attackers actually accessed.

Only a "very few" clients were affected, the company said. "No disruption has occurred to client businesses, to Deloitte's ability to continue to service clients, or to consumers," the statement noted. Deloitte immediately informed the appropriate government authorities upon breach discovery and contacted each of the clients that were affected, it added.

It's unclear how the threat actor might have obtained access to the administrator account that The Guardian reported as being used for the theft. But the company's apparent failure to properly protect it came in for some criticism Monday from security executives. 

Several feel that the company, as one of the largest cybersecurity consultancies in the industry, should have known better than to use a single password for the account, especially at a time when credential theft and misuse have become rampant.

"Clearly, they don't exactly practice what they preach," says Gaurav Banga, founder and CEO of Balbix. Based on the details available so far, the attack itself does not appear to be particularly sophisticated, he says. "If there is no two-factor authentication on administrative accounts, and unencrypted emails are floating around, then the adversary does not need to work very hard after an initial breach-head is established."

The apparent fact that Deloitte did not discover the intrusion for several months is not entirely surprising in this context, adds Rich Campagna, CEO of Bitglass.

"Breaches involving credential compromise often take months to identify and remediate," he says. "From an IT perspective, it can be difficult to notice unusual activity from hijacked accounts — it may simply appear that users are going about their jobs normally. At Deloitte's scale, manual review of each somewhat suspicious transaction isn't a feasible option."

The main takeaway from incidents like these is that organizations must mandate two-factor authentication on all external accounts and services, adds Mark Dufresne, director of threat research and adversary prevention at Endgame.

"This is another example of a case in which the actors didn't need exploits or malware to gain access," says Dufresne, "but were simply able to capitalize on employees' poor cyber hygiene."

Related content:

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industrys most knowledgeable IT security experts. Check out the INsecurity agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
9/26/2017 | 9:11:37 AM
Thoughts
2 Factor identification is mandatory.  Eliminate SSNumber as an authentication tool.  Do not OUTSOURCE - and the big 4 do outsource AUDIT controls that that Bastion of all things CHEAP ----- INDIA.  Be truthful and forthright about a breach situation.  Tell ALL the truth at once.  
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
WSJ Report: Facebook Breach the Work of Spammers, Not Nation-State Actors
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/19/2018
4 Ways to Fight the Email Security Threat
Asaf Cidon, Vice President, Content Security Services, at Barracuda Networks,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Latest Comment: Too funny!
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.