Only days after Equifax suffered one of the largest data breaches in recent history, The Guardian reports that Deloitte, one of the world’s largest accountancy firms has suffered a ‘sophisticated hack’ which gave the attackers access to the company’s e-mail servers as an administrator.
This gave the hackers access to all of the data sent via e-mail, including attachments, affecting many of the company’s biggest clients, including government departments from numerous countries, banks and multinational corporations in media, healthcare and other industries.
Professor Bill Buchanan OBE, the head of Edinburgh Napier University’s Cyber Academy, told DIGIT: “This attack is another example of companies not taking security seriously. To have a single password for the administrator account for a financial services company is extremely sloppy. Increasingly companies need to be using multi-factor authentication for administrator access. This should include “out-of-band” methods, such as using an additional access step through a mobile phone. With an increasing number of companies using Cloud-based email systems, they need to understand that they need to increase security and apply encryption wherever possible, and especially lock-down access from trusted places.”
Award Winning Cyber Security Consultancy
Deloitte’s investigation into the incident is ongoing, but according to The Guardian, six of the company’s clients have so far been informed that their data was ‘impacted’. The incident is doubly troubling for Deloitte as the company – which was ranked the world’s best cyber security consultancy in 2012 – offers advice to clients on cyber security and avoiding attacks similar to the one it has suffered.
Deloitte’s website states: “Cyber risk is more than a technology or security issue, it is a business risk. While today’s fast-paced innovation enables strategic advantage, it also exposes businesses to potential cyber-attack. Embedding best practice cyber behaviours help our clients to minimise the impact on business.”
“We monitor and assess the threats specific to your organisation, enabling you to swiftly and effectively mitigate risk and strengthen your cyber resilience. Going beyond the technical feeds, our professionals are able to contextualise the relevant threats, helping determine the risk to your business, your customers and your stakeholders.”
The breach, which is currently believed to have primarily focused on the USA, was regarded as so confidential that only Deloitte’s most senior partners (and lawyers) were informed.
The Guardian says the company has now involved specialist investigators, to to map out exactly where the hackers went, by analysing the which searches the hacker(s) carried out.
There is no information on whether the hack was the work of an individual, rival companies or state-sponsored hackers. The Guardian suggests that 5 million e-mails may have been vulnerable in the attack, however Deloitte states that the hack affected ‘a fraction’ of that number.
Security expert Stu Hirst, the Head of SecOps for Capital One, said: “Major businesses will continue to be targets for hackers given the value of information that can potentially be obtained. As our industries become cloud-first, it has never been more important to adopt world-class security practices & procedures to protect against data loss. Email especially continues to be a medium where vitally sensitive information is shared, so encrypting in transit & at rest should be mechanisms to prevent secrets being deciphered.”
Deloitte Responds
A spokesman for Deloitte told The Guardian: “In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,”
“As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators.
“The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers.
“We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required.
“Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”
Dr Jamie Graves, the founder and CEO of security specialists Zonefox was very clear on the causes of the hack: “This attack is another clear example that anyone can be affected by cybercriminals – even those whose speciality is to stop them. It’s discomforting to see that even an experienced firm as Deloitte have fallen victim to attackers supposedly using an administrative password and account to access their Azure storage. This has to act as a wake-up call for the industry to pursue a more proactive, threat-hunting approach to their cyber-security.
“Passwords still have a hugely important role to play in securing information, but they have to be combined with other layers of security within a two or multi-factor approach. The bottom line is that data visibility has to be in place for an effective, modern security structure; firms need to know not just who is accessing their data, but where it’s being accessed from, what has specifically been looked at and where the data (or copies of it) is residing, while stationary and in transit.
“Extra layers – such as IP listing and user behaviour analytics – would have helped Deloitte identify that outside agents were using the administrative account; certainly reducing the time the attackers spent within the network before being noticed. Months of access combined with six months of behind-the-scenes work before the attack has come to general attention would certainly fall foul of GDPR once it goes live and does little to generate sympathy for the firm. It’s a worthy tactic to try and trace the cyber-footsteps of the attackers now, but a more proactive approach, utilising machine learning and augmented or artificial intelligence, will ensure firms can identify threats before they can create a major security concern.”





