Back Heise.De Whistleblower accuses IBM and AT&T of covering up foreign cyberattacks
US corporations IBM and AT&T are repeatedly exposed to cyberattacks from abroad. Because they do business with the US government, they are obligated to report breaches and data exfiltration. According to a lawsuit filed by a former IBM security expert, this has not happened, or not to the full extent. He accuses the companies of having covered up successful attacks by foreign cybercriminals to secure new government contracts and continue existing agreements with the US government.
The lawsuit against IBM and AT&T was filed in a New York federal court back in 2020 and is still pending. However, it only became public now after the US government did not exercise its option to intervene in the proceedings. The plaintiff is William Barlow, who worked at IBM as Vice President of Threat Intelligence until 2019. The reasons for his departure are not known.
In the lawsuit, the whistleblower states that unknown cybercriminals from abroad have repeatedly infiltrated IBM's extensive cloud infrastructure, the networking of which is operated by AT&T. Parts of this cloud system are also used by the US government, including the military. In some cases, the corporations could not determine where the attackers came from or what they had stolen. IBM downplayed or covered this up, even though government contracts require the disclosure of major unresolved cybersecurity issues.
One of the cyberattacks on IBM listed in the lawsuit was carried out by two state- cybercriminals from China, allegedly belonging to the well-known APT10 group (Advanced Persistent Threat 10). According to the US Department of Justice , they stole data from 100,000 US Navy personnel in 2018. Intelligence agencies also informed IBM that APT10 was using IP addresses from the IBM network.
From 2013 to 2016, IBM discovered 50,000 “potential APT10 hits” during an internal investigation. The following year, according to the lawsuit, IBM found that attackers had gained access to almost 400 compromised user accounts and almost 200 systems and servers in 18 countries. However, as IBM does not keep access logs, the company could not investigate further, according to the plaintiff.
“The data breaches are so large and the core networks so poorly designed that neither IBM nor AT&T knows exactly what data was breached, who breached the data, where the data was breached, or whether any data was exfiltrated, altered, and/or modified in any respect,” according to Bloomberg , the lawsuit states.
Although Barlow was questioned by government agencies the alleged cyberattacks from China, he was instructed to evade them. Executives also pressured him to downplay internal reports and omit details. He knows of several cases where IBM's top management actively took steps to cover up cyberattacks and hide them from US authorities and government clients. However, Barlow does not name names in the lawsuit.
The lawsuit is based on the “False Claims Act,” the US law against false claims. According to this, individuals and organizations can be held liable if they have profited through fraud and other criminal acts. The Department of Justice can join the lawsuit to recover damages. The law encourages whistleblowers to expose such malpractices through legal action by allowing them to receive a portion of the damages paid to the state.
“This complaint was filed six years ago, and the US Department of Justice declined to intervene,” explains IBM spokesman Adam Pratt. “IBM is confident that our actions followed the letter of the law.” AT&T has not yet responded to a corresponding request, nor have the US Department of Defense and the US Department of Justice.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
