Site navigation

Deloitte Hacked: Banks, Government Agencies & Multinationals Data Breached

Brian Baglow

,

Deloitte email hack

One of the world’s ‘big four’ accountancy firms may have had security compromised since the end of 2016.

It is suspected that hackers gained access to the company’s global e-mail server through an administrator account secured with only a single password.

Only days after Equifax suffered one of the largest data breaches in recent history,  The Guardian reports that Deloitte, one of the world’s largest accountancy firms has suffered a ‘sophisticated hack’ which gave the attackers access to the company’s e-mail servers as an administrator.

This gave the hackers access to all of the data sent via e-mail, including attachments, affecting many of the company’s biggest clients, including government departments from numerous countries, banks and multinational corporations in media, healthcare and other industries.

Professor Bill Buchanan OBEProfessor Bill Buchanan OBE, the head of Edinburgh Napier University’s Cyber Academy, told DIGIT: “This attack is another example of companies not taking security seriously. To have a single password for the administrator account for a financial services company is extremely sloppy. Increasingly companies need to be using multi-factor authentication for administrator access. This should include “out-of-band” methods, such as using an additional access step through a mobile phone. With an increasing number of companies using Cloud-based email systems, they need to understand that they need to increase security and apply encryption wherever possible, and especially lock-down access from trusted places.”

Award Winning Cyber Security Consultancy

Deloitte’s investigation into the incident is ongoing, but according to The Guardian, six of the company’s clients have so far been informed that their data was ‘impacted’. The incident is doubly troubling for Deloitte as the company – which was ranked the world’s best cyber security consultancy in 2012 – offers advice to clients on cyber security and avoiding attacks similar to the one it has suffered.

Deloitte’s website states: “Cyber risk is more than a technology or security issue, it is a business risk. While today’s fast-paced innovation enables strategic advantage, it also exposes businesses to potential cyber-attack. Embedding best practice cyber behaviours help our clients to minimise the impact on business.”

“We monitor and assess the threats specific to your organisation, enabling you to swiftly and effectively mitigate risk and strengthen your cyber resilience. Going beyond the technical feeds, our professionals are able to contextualise the relevant threats, helping determine the risk to your business, your customers and your stakeholders.”

The breach, which is currently believed to have primarily focused on the USA, was regarded as so confidential that only Deloitte’s most senior partners (and lawyers) were informed.

The Guardian says the company has now involved specialist investigators, to to map out exactly where the hackers went, by analysing the which searches the hacker(s) carried out.

There is no information on whether the hack was the work of an individual, rival companies or state-sponsored hackers. The Guardian suggests that 5 million e-mails may have been vulnerable in the attack, however Deloitte states that the hack affected ‘a fraction’ of that number.

Stu Hirst, an experienced voice in CISOSecurity expert Stu Hirst, the Head of SecOps for Capital One, said: “Major businesses will continue to be targets for hackers given the value of information that can potentially be obtained. As our industries become cloud-first, it has never been more important to adopt world-class security practices & procedures to protect against data loss. Email especially continues to be a medium where vitally sensitive information is shared, so encrypting in transit & at rest should be mechanisms to prevent secrets being deciphered.”

 

Deloitte Responds

A spokesman for Deloitte told The Guardian: “In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,”

“As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators.

“The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers.

“We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required.

“Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”

Jamie Greaves on Scottish tech talentDr Jamie Graves, the founder and CEO of security specialists Zonefox was very clear on the causes of the hack: “This attack is another clear example that anyone can be affected by cybercriminals – even those whose speciality is to stop them. It’s discomforting to see that even an experienced firm as Deloitte have fallen victim to attackers supposedly using an administrative password and account to access their Azure storage. This has to act as a wake-up call for the industry to pursue a more proactive, threat-hunting approach to their cyber-security.

“Passwords still have a hugely important role to play in securing information, but they have to be combined with other layers of security within a two or multi-factor approach. The bottom line is that data visibility has to be in place for an effective, modern security structure; firms need to know not just who is accessing their data, but where it’s being accessed from, what has specifically been looked at and where the data (or copies of it) is residing, while stationary and in transit.

“Extra layers – such as IP listing and user behaviour analytics – would have helped Deloitte identify that outside agents were using the administrative account; certainly reducing the time the attackers spent within the network before being noticed. Months of access combined with six months of behind-the-scenes work before the attack has come to general attention would certainly fall foul of GDPR once it goes live and does little to generate sympathy for the firm. It’s a worthy tactic to try and trace the cyber-footsteps of the attackers now, but a more proactive approach, utilising machine learning and augmented or artificial intelligence, will ensure firms can identify threats before they can create a major security concern.”

Movers and shakers

Brian Baglow

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data