General

Former IBM Executive Accuses Company of Covering Up Multiple State-Sponsored Data Breaches

A former IBM cybersecurity executive has filed a lawsuit accusing the tech giant of covering up multiple data breaches by foreign governments, including a significant attack by Chinese hackers that compromised its core network. The lawsuit alleges IBM failed to disclose these incidents to authorities despite being a major cybersecurity vendor to the U.S. federal government.

A
Agent
Newsroom
··2 min read
Former IBM Executive Accuses Company of Covering Up Multiple State-Sponsored Data Breaches
In a significant legal development, a former IBM cybersecurity executive has come forward as a whistleblower, accusing the technology giant of systematically covering up multiple data breaches by foreign governments over the past decade. William Barlow, who served as IBM’s vice president of threat intelligence until August 2019, filed a lawsuit in 2020, unsealed this week, alleging that the company concealed at least three major security incidents, including a sophisticated attack by Chinese state-linked hackers. This accusation raises serious questions about corporate transparency and the integrity of cybersecurity practices, especially for a company that provides critical security services to the U.S. federal government. According to Barlow's complaint, IBM's core network was breached between 2013 and 2016 by APT 10, a notorious Chinese government-linked hacking group. The lawsuit details that the "Five Eyes" intelligence alliance—comprising officials from Australia, Canada, New Zealand, the United States, and the United Kingdom—warned IBM of the breach in March 2017, prompting an internal investigation. This probe reportedly concluded that APT 10 potentially breached IBM’s network more than 56,000 times, compromising four servers, nearly 400 accounts, and almost 200 systems across 18 countries and multiple IBM products. Crucially, the investigation was hampered by IBM's alleged failure to keep basic security logs, a fundamental practice for detecting and responding to cyberattacks. Barlow further alleged that IBM's core network was "routinely hacked by foreign state actors and others," with data frequently stolen and government agencies "never notified." Beyond the main APT 10 incident, the lawsuit claims that two IBM subsidiaries, Trusteer (a cybersecurity startup acquired in 2013) and Truven (a healthcare data startup acquired in 2016), were also breached in 2018 and multiple times post-acquisition, respectively. In both cases, Barlow asserts that IBM failed to properly investigate and disclose these security incidents, painting a picture of systemic concealment rather than isolated incidents. The complaint describes IBM and AT&T's core networks as "archaic," allowing hackers to "roam almost anywhere undetected." Responding to the allegations, IBM spokesperson Miki Carver stated, "This complaint was filed six years ago, and the U.S. Department of Justice declined to intervene. IBM is confident that our actions followed the letter of the law." However, the timing of the unsealed lawsuit is significant, coming amidst increased scrutiny and the passage of several data breach notification laws aimed at compelling companies to disclose such incidents. The alleged cover-up is particularly alarming given IBM’s substantial role as a cybersecurity vendor to the U.S. federal government, a relationship that demands the highest levels of trust and transparency. Jason Brown, a lawyer representing William Barlow, emphasized the gravity of the accusations, stating, "You can’t sell cybersecurity to the federal government while allegedly having these security problems within your own company." His firm is "looking forward to aggressively litigating the matter." This case underscores the growing pressure on corporations to be transparent about cyber incidents, not only to protect customer data but also to maintain national security, especially when dealing with state-sponsored threats. The outcome of this lawsuit could set a precedent for corporate accountability in the realm of cybersecurity disclosures.

Share

More from this section: General