Deloitte hit by cyber security incident

Image

Deloitte has confirmed it was the victim of a cyber attack which saw hackers gain access to the Big Four firm’s email system over a lengthy period of time, with the ability to view sensitive client data

News of the incursion first surfaced in a Guardian report this week, but Deloitte is believed to have been aware of the security breach in March, with suggestions that the attack may have begun in the autumn of last year.

The hacker is believed to have entered Deloitte’s systems via its email service for staff, which is stored in the Azure cloud service provided by Microsoft. There are suggestions that the account required only a single password and did not have ‘two-step’ verification.

In a statement acknowledging the cyber incident, Deloitte confirmed the attacker accessed data from an email platform, and said a review of the platform is now complete.

Deloitte’s statement continued: ‘Importantly, the review enabled us to understand precisely what information was at risk and what the hacker actually did and to determine that: only very few clients were impacted, and no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers.’

Media reports suggest that around six US-based clients have been affected by the data breach, although the firm has given no indication of the number or locations of any incidents.

Deloitte said it had contacted ‘each of the very few clients impacted’ and had alerted government authorities immediately after it became aware of the incident. It has also mobilised a team of cyber-security and confidentiality experts inside and outside of Deloitte.

The statement concluded: ‘Deloitte remains deeply committed to ensuring that its cyber-security defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cyber security.’

News of Deloitte’s cyber security breakdown comes a week after US credit report giant Equifax admitted that data it held on up to 143 million Americans, about 400,000 Britons and a number of Canadians may have been stolen by hackers between mid-May and July. The information included credit card payment histories, social security numbers and other personal details. 

Report by Pat Sweet

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe