Deloitte has denied recent allegations that it suffered a data breach after a ransomware group claimed to have breached its systems and threatened to publish the stolen data.
Following an internal investigation, Deloitte has responded to the allegations, saying that the claim related to a single system of one of their clients which reside outside of their internal network.
According to a spokesperson, “No Deloitte systems have been impacted,” as reported by Infosecurity Magazine.
The ransomware group responsible for the claim, Brain Cipher, first said that they stole 1 TB of compressed data from the firm, in an allegation published on 4 December.
The group claimed that large organisations do not always “do their jobs well,” alleging that Deloitte had skipped out on practical and ‘elementary points’ of security.
The group further hinted at persistent access to Deloitte’s systems, stating, “We are still using [tools] there today.” Brain Cipher promised to disclose evidence of alleged failures in Deloitte’s security protocols with a countdown of ten days from the original post, suggesting that “the fundamentals of computer security were not respected” and claiming they would provide examples of how they bypassed the firm’s defenses.
Recommended reading
- New Report Highlights Collabs Between Nation-states, Cyber-crime Rings
- NCSC Issues Warning Over Iran Spear-Phishing Attacks
- 67% of Healthcare Organisations Hit by Ransomware In the Past Year
Brain Cipher, which appeared in June 2024, has quickly built a reputation for aggressive tactics, including targeting critical industries such as healthcare, education, and government entities.
Known for leveraging LockBit 3.0-based ransomware, the group employs phishing and spear-phishing as entry points before deploying its payload.
It has already orchestrated high-profile attacks, including a disruptive breach of Indonesia’s National Data Center earlier this year, which severely disrupted public services such as immigration processing and new student registration systems.
But why would a profiteering ransomware gang lie about a data breach?
The data breach may lead to little monetary benefit on behalf of the ransomware group, but can lead to severe reputational damage even if a claim is refuted and found to be a lie.





