RSA disclosed that attackers carried out an advanced persistent threat intrusion against its internal systems and stole information related to its SecurID two-factor authentication products. EMC said the compromise did not appear to expose customer or employee personally identifiable information, other RSA products, or other EMC products, but warned that the stolen data could reduce the effectiveness of existing SecurID deployments if used as part of a broader attack. The company said it notified customers, worked with authorities, hardened affected systems, and issued guidance through SecurCare Online to help organizations strengthen their SecurID implementations.
RSA later described the intrusion as a targeted spear-phishing campaign in which employees received emails with the subject "2011 Recruitment Plan" and an attached Excel file that exploited the Adobe Flash zero-day CVE-2011-0609 to install a backdoor and a customized Poison Ivy remote access trojan. The attackers harvested credentials, escalated privileges, moved laterally, staged data internally, and exfiltrated it via FTP in password-protected RAR archives to an external compromised host. EMC said the breach ultimately cost at least $66.3 million for investigation, infrastructure hardening, customer monitoring, and replacement of some SecurID tokens, and later reporting linked the stolen information to follow-on targeting, including an attempted attack on Lockheed Martin.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
EMC disclosed that the RSA breach had cost at least $66.3 million, covering investigation, IT hardening, customer transaction monitoring, and replacement of some SecurID tokens. EMC said its investigation suggested the attackers were likely seeking information tied to government and military accounts rather than financial data.
RSA released a detailed account of the attack chain, describing the spear-phishing lure, exploitation of CVE-2011-0609, deployment of a customized Poison Ivy remote access trojan, privilege escalation, lateral movement, and FTP exfiltration of password-protected RAR archives. The post also noted RSA detected the intrusion while it was still in progress.
Following the disclosure, RSA said it was actively notifying customers and providing immediate steps through a SecurCare Online note to strengthen SecurID deployments. The company also said it had taken aggressive defensive measures, hardened its infrastructure, launched an extensive investigation, and worked with appropriate authorities.
RSA publicly disclosed that it had been targeted in an extremely sophisticated cyberattack and that attackers extracted information specifically related to its SecurID two-factor authentication products. The company said it had no evidence other RSA products, other EMC products, or customer and employee personally identifiable information were compromised.
A targeted APT campaign against RSA began with spear-phishing emails titled "2011 Recruitment Plan" sent to small groups of employees. After an employee opened a malicious Excel attachment exploiting Adobe Flash vulnerability CVE-2011-0609, the attackers installed malware, stole credentials, moved laterally, and exfiltrated data from RSA systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.