Attacks/Breaches

9/25/2017
03:50 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Breach at Deloitte Exposes Emails, Client Data

Intrusion may have resulted from company's failure to properly secure a key administrator account.

Big Four accounting giant and cybersecurity consultancy Deloitte has suffered a data breach that ironically enough may have resulted from the firm's failure to follow its own security advice to clients.

The Guardian on Monday reported that an intrusion at Deloitte between October and November last year exposed emails containing highly sensitive data belonging to an unknown number of large US companies and government organizations.

The intrusion, which Deloitte did not discover until March 2017, apparently stemmed from the company's failure to use two-factor authentication to protect a critical administrator account — something that it advocates as a best practice for clients. Attackers used the account to get privileged and unrestricted access to Deloitte's entire Azure-hosted email system.

During the multiple months that the threat actors managed to remain undetected on Deloitte's network, they potentially had access to some 5 million emails. The attackers also had potential access to usernames, passwords, health information, and highly sensitive data belonging to an unspecified number of Deloitte's clients, The Guardian said.

Deloitte itself has claimed that the actual number of emails and the scope of the data that was affected is only a "fraction" of the number suggested by The Guardian.

In an emailed statement to Dark Reading, Deloitte confirmed the breach and said the attackers had accessed data from the company's email platform. Deloitte's investigation of the incident has enabled it to understand precisely what data was at risk and what the attackers actually accessed.

Only a "very few" clients were affected, the company said. "No disruption has occurred to client businesses, to Deloitte's ability to continue to service clients, or to consumers," the statement noted. Deloitte immediately informed the appropriate government authorities upon breach discovery and contacted each of the clients that were affected, it added.

It's unclear how the threat actor might have obtained access to the administrator account that The Guardian reported as being used for the theft. But the company's apparent failure to properly protect it came in for some criticism Monday from security executives. 

Several feel that the company, as one of the largest cybersecurity consultancies in the industry, should have known better than to use a single password for the account, especially at a time when credential theft and misuse have become rampant.

"Clearly, they don't exactly practice what they preach," says Gaurav Banga, founder and CEO of Balbix. Based on the details available so far, the attack itself does not appear to be particularly sophisticated, he says. "If there is no two-factor authentication on administrative accounts, and unencrypted emails are floating around, then the adversary does not need to work very hard after an initial breach-head is established."

The apparent fact that Deloitte did not discover the intrusion for several months is not entirely surprising in this context, adds Rich Campagna, CEO of Bitglass.

"Breaches involving credential compromise often take months to identify and remediate," he says. "From an IT perspective, it can be difficult to notice unusual activity from hijacked accounts — it may simply appear that users are going about their jobs normally. At Deloitte's scale, manual review of each somewhat suspicious transaction isn't a feasible option."

The main takeaway from incidents like these is that organizations must mandate two-factor authentication on all external accounts and services, adds Mark Dufresne, director of threat research and adversary prevention at Endgame.

"This is another example of a case in which the actors didn't need exploits or malware to gain access," says Dufresne, "but were simply able to capitalize on employees' poor cyber hygiene."

Related content:

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industrys most knowledgeable IT security experts. Check out the INsecurity agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
9/26/2017 | 9:11:37 AM
Thoughts
2 Factor identification is mandatory.  Eliminate SSNumber as an authentication tool.  Do not OUTSOURCE - and the big 4 do outsource AUDIT controls that that Bastion of all things CHEAP ----- INDIA.  Be truthful and forthright about a breach situation.  Tell ALL the truth at once.  
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure Mentem,  7/19/2018
Number of Retailers Impacted by Breaches Doubles
Ericka Chickowski, Contributing Writer, Dark Reading,  7/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19990
PUBLISHED: 2018-07-23
October CMS version prior to build 437 contains a Cross Site Scripting (XSS) vulnerability in the Media module and create folder functionality that can result in an Authenticated user with media module permission creating arbitrary folder name with XSS content. This attack appear to be exploitable v...
CVE-2018-19990
PUBLISHED: 2018-07-23
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote code execution. This attack appear to be exploitable remotely if the /backend pat...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can result in attackers accessing out of bound data. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fix...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit 2b46ebdbff1d8dec7a3d8ea280a612b91a582869 contains a Buffer Overflow vulnerability in asf_o format demuxer that can result in heap-buffer-overflow that may result in remote code execution. This attack appears to be exploitable via specially crafted ASF file that has to be provide...
CVE-2018-19990
PUBLISHED: 2018-07-23
FFmpeg before commit 9807d3976be0e92e4ece3b4b1701be894cd7c2e1 contains a CWE-835: Infinite loop vulnerability in pva format demuxer that can result in a Vulnerability that allows attackers to consume excessive amount of resources like CPU and RAM. This attack appear to be exploitable via specially c...