RSA disclosed that attackers breached systems tied to its SecurID two-factor authentication platform and stole sensitive information that could weaken the security of deployed tokens. Subsequent reporting said the intrusion began with a spearphishing email carrying an Excel file, 2011 Recruitment plan.xls, that exploited Adobe Flash zero-day CVE-2011-0609 to install the Poison Ivy backdoor; the attackers then escalated privileges, moved laterally, staged data internally, and exfiltrated encrypted files over FTP through an external compromised host. The central unanswered question was whether the attackers obtained token seed values, serial-number mappings, or related databases that underpin SecurID authentication.
The breach quickly raised operational risk for major customers, and Lockheed Martin later confirmed that hackers used information stolen from RSA in an attempted network intrusion, though the company said it detected and stopped the attack before significant damage occurred. In response, Lockheed replaced 45,000 SecurID tokens, forced password resets, and added another authentication layer, while EMC later said the RSA incident cost at least $66.3 million for investigation, system hardening, customer monitoring, and token replacement. Reporting at the time said the attackers were likely seeking access related to government and military accounts, and the incident became a defining example of how a compromise at a security vendor can cascade into downstream threats for thousands of enterprise and public-sector customers.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
EMC disclosed that the RSA incident had cost at least $66.3 million, covering investigation, IT hardening, customer monitoring, and replacement of some SecurID tokens. The company said its investigation suggested the attackers were likely seeking information related to government and military accounts rather than financial data.
Lockheed Martin confirmed that hackers attempted to breach its systems using information stolen in RSA's March compromise, validating fears of follow-on attacks against SecurID customers. Lockheed said it detected and stopped the intrusion before significant data loss, then replaced 45,000 SecurID tokens, forced password changes, and added another authentication step.
RSA executive Uri Rivner disclosed that the intrusion began with spearphishing emails carrying an Excel file named "2011 Recruitment plan.xls" that exploited Adobe Flash zero-day CVE-2011-0609 and installed a Poison Ivy backdoor. He said the attackers then escalated privileges, moved laterally, staged data internally, and exfiltrated encrypted archives via FTP through an external compromised host.
As RSA continued to withhold specifics, public reporting emphasized that customers should assume critical SecurID components may have been exposed and strengthen defenses such as PINs and monitoring. The lack of transparency drew criticism and raised concerns that some customers might abandon the product.
Following RSA's disclosure, analysts and industry observers warned that if attackers obtained SecurID seed records, serial-number mappings, or details of seed generation, the security of affected tokens could be materially reduced. They also cautioned that high-value targets could face elevated risk and that phishing exploiting fear around the breach was likely.
RSA revealed that it had suffered a cyber intrusion in March 2011 and said attackers stole confidential information related to its SecurID two-factor authentication product. The company did not publicly specify whether token seed values or seed-to-serial mapping data were taken, leaving customers uncertain about the practical impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourcenytimes.com
Open sourcetheregister.co.uk
Open sourcetheregister.co.uk
Open sourceweb.archive.org
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.