首页 500强 活动 榜单 商业 科技 商潮 专题 品牌中心
杂志订阅

吹哨人指控:IBM、AT&T掩盖境外黑客入侵事件

诉讼罕见地揭露了两家主要政府承包商存在的安全漏洞,引发了公众对网络敏感信息保护以及企业就此类安全漏洞履行披露义务情况的质疑。

文本设置
小号
默认
大号
Plus(0条)

吹哨人针对IBM和AT&T的诉讼材料于2020年密封提交,目前仍在纽约联邦法院待审。图片来源:Getty Images—Matthias Balk/picture alliance

IBM前网络安全官员提起的诉讼称,IBM和美国电话电报公司(以下简称AT&T)的计算机系统曾多次遭到境外黑客入侵,两家公司未依法向美国政府披露这些入侵事件,涉嫌违法。

IBM前威胁情报副总裁威廉·巴洛(William Barlow)在起诉书中指控,两家公司多年来隐瞒多起境外政府关联的攻击者发起的入侵事件,并就自身系统安全性作出虚假保证,以获取并维持联邦政府合同。

吹哨人针对IBM和AT&T的诉讼材料于2020年密封提交,目前仍在纽约联邦法院待审。上周,在美国政府决定不予介入后,诉状才被公开,相关内情此前从未见报。

该诉讼罕见地揭露了两家主要政府承包商存在的安全漏洞,引发了公众对网络敏感信息保护以及企业就此类安全漏洞履行披露义务情况的质疑。

起诉书披露,黑客入侵了IBM庞大的云计算基础设施——该系统广泛用于包括军方在内的多个美国政府部门。根据诉状,AT&T代表IBM运营这一“核心网络”,这家总部位于达拉斯的电信公司的系统也是该网络的组成部分。

起诉书指控,境外身份不明的黑客多次渗透该网络,两家公司有时无法确定入侵者身份或被窃取信息。诉状还指出,IBM在签署政府协议前淡化或隐瞒了相关事件,而相关协议要求IBM证明其不存在尚未解决的重大网络安全问题。

IBM发言人亚当·普拉特(Adam Pratt)表示:“这起诉讼是六年前提起的,美国司法部决定不予介入。IBM坚信自身行为符合法律规定。”

AT&T的代表未回应置评请求。

根据诉状,巴洛自2002年起两度供职于IBM,2017年出任威胁情报副总裁,直至2019年辞职。2018年《纽约时报》一篇关于IBM在定制半挂卡车打造的移动指挥中心提供网络安全培训的报道中,曾援引其观点。离职后,巴洛持续活跃于网络安全领域,出席行业会议并发表演讲。

巴洛的律师贾森·T·布朗(Jason T. Brown)拒绝讨论当事人离职的具体情况,也未透露美国司法部是否对《虚假申报法》诉讼中的指控展开调查。布朗表示,政府决定介入此类案件通常需要数年时间,而联邦官员选择不介入并不代表诉讼缺乏依据。他补充称,这些指控牵涉AT&T和IBM数十亿美元的联邦政府业务。

任职于Brown, LLC律所的布朗表示:“我们将全力推进此案的诉讼进程。如果一家公司内部确实存在这些安全问题,就无法向联邦政府兜售网络安全服务。”

巴洛在诉状中称,他亲眼目睹IBM核心网络多次遭到黑客入侵,高管施压要求他淡化内部报告内容并省略细节。巴洛指控称,他掌握多起IBM高层管理人员“主动采取措施,向美国监管机构和政府客户隐瞒和掩盖”黑客攻击事件的具体信息。

诉状称:“数据泄露规模庞大,核心网络设计存在重大缺陷,因此,IBM和AT&T无法确切知道泄露的数据明细、入侵主体与入侵节点,以及是否有数据遭窃取、篡改或是任何形式的改动。”

《虚假申报法》禁止向美国政府提交虚假索赔,要求支付相关款项。该法律允许吹哨人就涉嫌欺诈政府的行为提起诉讼。联邦当局可介入并实际接管此类案件。政府最高可追回三倍于损失的赔偿金,举报人可获得其中的一部分。

今年春季,在美国政府决定不介入后,纽约一名联邦法官裁定解封本案卷宗。法院记录未对政府决定作出解释,巴洛的律师布朗表示,他不清楚政府为何作出这一决定。

美国国防部和司法部未回复电子邮件问询。(财富中文网)

译者:中慧言-王芳

IBM前网络安全官员提起的诉讼称,IBM和美国电话电报公司(以下简称AT&T)的计算机系统曾多次遭到境外黑客入侵,两家公司未依法向美国政府披露这些入侵事件,涉嫌违法。

IBM前威胁情报副总裁威廉·巴洛(William Barlow)在起诉书中指控,两家公司多年来隐瞒多起境外政府关联的攻击者发起的入侵事件,并就自身系统安全性作出虚假保证,以获取并维持联邦政府合同。

吹哨人针对IBM和AT&T的诉讼材料于2020年密封提交,目前仍在纽约联邦法院待审。上周,在美国政府决定不予介入后,诉状才被公开,相关内情此前从未见报。

该诉讼罕见地揭露了两家主要政府承包商存在的安全漏洞,引发了公众对网络敏感信息保护以及企业就此类安全漏洞履行披露义务情况的质疑。

起诉书披露,黑客入侵了IBM庞大的云计算基础设施——该系统广泛用于包括军方在内的多个美国政府部门。根据诉状,AT&T代表IBM运营这一“核心网络”,这家总部位于达拉斯的电信公司的系统也是该网络的组成部分。

起诉书指控,境外身份不明的黑客多次渗透该网络,两家公司有时无法确定入侵者身份或被窃取信息。诉状还指出,IBM在签署政府协议前淡化或隐瞒了相关事件,而相关协议要求IBM证明其不存在尚未解决的重大网络安全问题。

IBM发言人亚当·普拉特(Adam Pratt)表示:“这起诉讼是六年前提起的,美国司法部决定不予介入。IBM坚信自身行为符合法律规定。”

AT&T的代表未回应置评请求。

根据诉状,巴洛自2002年起两度供职于IBM,2017年出任威胁情报副总裁,直至2019年辞职。2018年《纽约时报》一篇关于IBM在定制半挂卡车打造的移动指挥中心提供网络安全培训的报道中,曾援引其观点。离职后,巴洛持续活跃于网络安全领域,出席行业会议并发表演讲。

巴洛的律师贾森·T·布朗(Jason T. Brown)拒绝讨论当事人离职的具体情况,也未透露美国司法部是否对《虚假申报法》诉讼中的指控展开调查。布朗表示,政府决定介入此类案件通常需要数年时间,而联邦官员选择不介入并不代表诉讼缺乏依据。他补充称,这些指控牵涉AT&T和IBM数十亿美元的联邦政府业务。

任职于Brown, LLC律所的布朗表示:“我们将全力推进此案的诉讼进程。如果一家公司内部确实存在这些安全问题,就无法向联邦政府兜售网络安全服务。”

巴洛在诉状中称,他亲眼目睹IBM核心网络多次遭到黑客入侵,高管施压要求他淡化内部报告内容并省略细节。巴洛指控称,他掌握多起IBM高层管理人员“主动采取措施,向美国监管机构和政府客户隐瞒和掩盖”黑客攻击事件的具体信息。

诉状称:“数据泄露规模庞大,核心网络设计存在重大缺陷,因此,IBM和AT&T无法确切知道泄露的数据明细、入侵主体与入侵节点,以及是否有数据遭窃取、篡改或是任何形式的改动。”

《虚假申报法》禁止向美国政府提交虚假索赔,要求支付相关款项。该法律允许吹哨人就涉嫌欺诈政府的行为提起诉讼。联邦当局可介入并实际接管此类案件。政府最高可追回三倍于损失的赔偿金,举报人可获得其中的一部分。

今年春季,在美国政府决定不介入后,纽约一名联邦法官裁定解封本案卷宗。法院记录未对政府决定作出解释,巴洛的律师布朗表示,他不清楚政府为何作出这一决定。

美国国防部和司法部未回复电子邮件问询。(财富中文网)

译者:中慧言-王芳

International Business Machines Corp. and AT&T Inc.’s computer systems were repeatedly breached by foreign hackers, and the companies concealed those intrusions from the US government in violation of the law, according to a lawsuit from a former IBM cybersecurity official.

William Barlow, IBM’s former vice president of threat intelligence, alleged in the complaint that the companies failed to disclose multiple breaches over years by attackers linked to foreign governments and made false assurances about the security of their systems in order to win and keep federal contracts.

The whistleblower complaint against IBM and AT&T was filed under seal in 2020 and is still pending before a federal court in New York. It was made public this week, after the US government declined to intervene in the case, and hasn’t been previously reported.

The suit offers a rare account of alleged security failures at two major government contractors. It raises questions about the protection of sensitive information on the networks, and about companies’ responsibility to disclose such compromises.

The hackers allegedly breached massive IBM cloud computing infrastructure that’s widely used by many parts of the US government, including the military. AT&T operates this “Core Network” on behalf of IBM, and the Dallas-based telecommunications company’s systems are part of them, according to the complaint.

The complaint alleges that foreign and unidentified hackers repeatedly infiltrated the network and that the companies sometimes couldn’t determine who got in, or what was taken. It also says IBM downplayed or concealed incidents before entering government agreements requiring it to certify it had no significant unresolved cybersecurity issues.

“This complaint was filed six years ago, and the US Department of Justice declined to intervene,” said IBM spokesperson Adam Pratt. “IBM is confident that our actions followed the letter of the law.”

Representatives of AT&T didn’t respond to requests for comment.

Barlow worked at IBM in two stints beginning in 2002, including serving as vice president of threat intelligence from 2017 until his resignation in 2019, according to the lawsuit. He was quoted in a 2018 New York Times report about IBM offering cyber trainings in a mobile command center built in a customized semitrailer truck. Since leaving the Armonk, New York-based company Barlow has maintained a profile in the security industry, attending conferences and giving talks.

Jason T. Brown, an attorney for Barlow, declined to discuss the circumstances of his client’s resignation or say whether the Justice Department has investigated the allegations in the False Claims Act suit. Government decisions to intervene in such cases often take years and federal officials choosing not to get involved doesn’t indicate the merit of a complaint, Brown said. He added that the allegations implicate billions of dollars of federal business with AT&T and IBM.

“We’re looking forward to aggressively litigating the matter,” said Brown, of the firm Brown, LLC. “You can’t sell cybersecurity to the federal government while allegedly having these security problem within your own company.”

In his suit, Barlow claimed he personally witnessed numerous breaches of IBM’s core network and was pressured by executives to soften internal reports and omit details. Barlow alleged he knew of specific instances where IBM senior management “actively took steps to cover up and conceal” hacks from US regulators and government clients.

“The data breaches are so large and the core networks so poorly designed that neither IBM nor AT&T knows exactly what data was breached, who breached the data, where the data was breached or whether any data was exfiltrated, altered and/or modified in any respect,” the lawsuit alleges.

The False Claims Act bars submitting false claims for payment to the US government. The law allows private whistleblowers to sue for alleged fraud against the government. Federal authorities may step in and effectively take control of such cases. The government can recover as much as three times its damages and whistleblowers can be awarded a portion of those damages.

A federal judge in New York ordered the suit be unsealed this spring after the US government declined to intervene. The court records don’t explain the government’s decision and Brown, Barlow’s attorney, said he didn’t know what motivated it.

The departments of Defense and Justice didn’t respond to emailed questions.

财富中文网所刊载内容之知识产权为财富媒体知识产权有限公司及/或相关权利人专属所有或持有。未经许可,禁止进行转载、摘编、复制及建立镜像等任何使用。
0条Plus
精彩评论
评论

撰写或查看更多评论

请打开财富Plus APP

前往打开