Don’t do SECURITY. Do business SECURELY.

RSA discloses breach affecting SecurID authentication tokens

Security firm RSA said attackers had stolen information relating to its SecurID two-factor tokens in an advanced persistent threat attack.

Security company RSA, a division of EMC, disclosed that it had been the target of an extremely sophisticated attack, which it classed as an advanced persistent threat. It said information relating to its SecurID two-factor authentication products had been extracted.

What happened

  • Executive chairman Art Coviello said the stolen information could potentially reduce the effectiveness of SecurID implementations.
  • SecurID tokens were widely used by governments and businesses; around 40 million were reportedly in use.
  • RSA later said the intrusion began with phishing emails carrying a malicious spreadsheet attachment.
  • RSA subsequently offered to replace tokens for many customers after reports that the stolen data was used in an attempted attack on defence contractor Lockheed Martin.

Why it mattered

The breach showed that even security vendors could be compromised and that attacks on a supplier could weaken the defences of its customers.

Lessons for organisations

Treat security suppliers as part of your attack surface: assess their controls, plan how you would respond if a supplier is breached, and use layered defences rather than relying on any single control. Phishing awareness remains a first line of defence.

Sources: The Register, Computer Weekly

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights