→ Back to Home
Cloud Security

IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks

International Business Machines Corp. and AT&T Inc. are facing serious allegations from a former IBM cybersecurity official, William Barlow, who claims the companies actively covered up repeated foreign hacking incidents from the U.S. government. The lawsuit, which was filed under seal in 2020 and only recently made public, asserts that these actions violated federal law and contractual obligations. According to Barlow's complaint, foreign and unidentified hackers repeatedly infiltrated a massive IBM cloud computing infrastructure. This infrastructure is critical, as it is extensively used by numerous U.S. government entities, including the military. AT&T, which operates a "Core Network" on behalf of IBM, also had its systems implicated in these breaches. The whistleblower's allegations paint a picture of significant security failures, claiming that the companies were sometimes unable to determine the identity of the attackers or precisely what data had been exfiltrated or altered. Furthermore, the lawsuit contends that IBM deliberately downplayed or outright concealed these incidents before entering into government agreements that required certifications of no significant unresolved cybersecurity issues. Barlow specifically alleged that he was aware of instances where senior IBM management took active steps to hide hacks from U.S. regulators and government clients. The complaint describes the data breaches as so extensive and the core networks as so poorly designed that neither IBM nor AT&T possessed a clear understanding of the compromised data, the perpetrators, the breach locations, or whether any data was exfiltrated, altered, or modified. The lawsuit highlights the critical nature of protecting sensitive information on these networks and raises fundamental questions about the responsibility of companies to disclose such compromises. While the U.S. government has declined to intervene in the case, the lawsuit remains pending before a federal court in New York, offering a rare public account of alleged security lapses at major government contractors. Some of the breaches cited in the suit allegedly involved Chinese government-backed hackers, underscoring the sophisticated nature of the threats. The implications of these allegations extend beyond the immediate parties, raising concerns about the integrity of cloud services provided to government agencies and the transparency required from contractors handling national security interests.
#cloud security#data breach#government contracts#whistleblower#cybersecurity#compliance
Read original source