Global accounting firm Deloitte confirms report that it was breached, downplays impact; source: it affected all company email, admin accounts, occurred in 2016
U.S. government agencies … William White / InvestorPlace : Deloitte Data Hack 2017: Clients' Secret Emails Exposed Michael Moore / IT ProPortal : Deloitte hit by major cybersecurity breach Mohit Kumar / The Hacker News : Deloitte Hacked — Cyber Attack Exposes Clients' Emails Janet Burns / Forbes : Deloitte Hack May Have Exposed Emails, Passwords Of Clients And Staff Sarah Kuranda / CRN : Deloitte Hit By Data Breach, Customer Information Reportedly Exposed BBC : Deloitte hit by data breach John Leyden / The Register : Sensitive client emails, usernames, passwords exposed in Deloitte hack Rhett Jones / Gizmodo : One of the World's Biggest Accounting Firms Hacked After Basic Security Goof Sara Salinas / CNBC : A cyberattack at Deloitte may have revealed blue-chip client information Mallory Locklear / Engadget : Major accounting firm Deloitte reports extensive cybersecurity breach Jeff John Roberts / Fortune : Deloitte Gets Hacked: What We Know So Far Ellen Tannam / Silicon Republic : 5 things you should know about the Deloitte data breach Carly Page / Inquirer : Deloitte hack exposes secret emails and plans from firm's blue-chip clients Erica Pandey / Axios : Deloitte's email server hit by cyber attack Zack Whittaker / ZDNet : Deloitte confirms hack exposed email system Tweets: @briankrebs : First the SEC has a breach, now Deloitte. And September isn't over yet. http://www.theguardian.com/... via @lasombra_br Kevin Beaumont / @gossithedog : Deloittes' US offices have everything from Netbios to RDP to Exchange Admin (single factor) etc etc etc. They should get an auditor. pic.twitter.com/C8aoN5YQMn Eric Geller / @ericgeller : Big news: Hackers broke into Deloitte through 2FA-less admin account and accessed data on wide range of clients. http://www.theguardian.com/... http://twitter.com/... Ben Hunt / @epsilontheory : Deloitte hack and SEC hack are *far* more systemically destabilizing than Equifax hack, but will get fraction of attention. http://twitter.com/... Richard Bejtlich / @taosecurity : “Deloitte discovered the hack in March this year, but it is believed the attackers may have had access to its systems since Oct or Nov 2016” http://twitter.com/... Nicholas Weaver / @ncweaver : Wow, the amount of money the attackers could have made through insider trading with this access is mind-boggling http://krebsonsecurity.com/... Troy Hunt / @troyhunt : It's getting to the point where a major data breach barely even seems newsworthy any more... http://www.theguardian.com/... Eric Geller / @ericgeller : Deloitte hack gets worse with new @briankrebs reporting. Company isn't sure if it fully kicked out the hackers. http://krebsonsecurity.com/... http://twitter.com/...
Context & Ripple Effects
Deloitte is confirming a breach that source reporting dates to 2016 and says reached all company email plus administrative accounts — the firm's own framing downplays impact, while coverage from The Register, Forbes, and CRN reports client emails, usernames, and passwords were exposed. It lands weeks after researchers found Accenture left a huge trove of sensitive data on exposed servers, putting both Big Four-scale consultancies' security claims under simultaneous scrutiny.
The pattern rhymes with the FBI's investigation of the suspected Russian DNC hack, where a compromised email system became the leak vector for an entire organization's internal communications — except here the compromised inbox belongs to a firm whose product is trusted advice on controls and risk.
First-order effects
- Clients whose correspondence sat in Deloitte's email system now face the possibility their confidential files, credentials, and strategic plans were readable by the intruder for months before detection.
- Deloitte must manage a disclosure gap: it confirmed the breach only after external reporting, so its 'limited impact' framing competes with the reported scope of full email and admin account access.
Second-order effects
- Rival consultancies — Accenture most immediately, given its own exposure disclosure the same season — get pulled into client due-diligence questions about whether any auditor or adviser can credibly certify security it cannot keep itself.
- Clients buying audit and advisory work gain leverage to renegotiate terms around data handling, since the breach shows the vendor relationship itself is the attack surface.
Third-order effects
- If email-plus-admin-account compromise keeps recurring across trusted intermediaries — from the DNC to Treasury workstations to consulting firms — client confidentiality assurance shifts from a firm-by-firm claim to a regulated disclosure question, with buyers demanding independent verification rather than self-attested 'no material impact' statements.
The trend: Email systems at high-trust intermediary firms are becoming the recurring breach vector of choice, forcing the professional-services industry to treat its own communications infrastructure as client-critical infrastructure.