A former IBM cybersecurity executive has accused the company of being hacked by foreign governments three times in the past decade and then covering up the breaches.
In a lawsuit filed in 2020 and unsealed this week, William Barlow, who served as IBM's vice president of threat intelligence until August 2019, said IBM concluded that Chinese hackers infiltrated the company's core network between 2013 and 2016, but that the company subsequently covered up the intrusion and never disclosed it. Barlow also said that at least two IBM subsidiaries were also breached, and that IBM covered up these breaches as well.
Barlow alleges in his complaint that IBM's core network is “routinely hacked by foreign state actors and others,” adding that data is frequently stolen and government agencies “are never notified.”
Although the alleged breach dates back more than a decade, news reports indicate that cyberattacks, even those affecting major technology companies such as IBM, are sometimes never disclosed to the general public or relevant government authorities. IBM is a major cybersecurity vendor for the U.S. federal government, which makes the allegations of a cover-up particularly serious. Several data breach notification laws have been passed in recent years to combat this problem.
Bloomberg first reported on the lawsuit.
IBM spokeswoman Miki Carver declined to answer specific questions about the lawsuit and its underlying accusations. Instead, Carver told TechCrunch, “This complaint was filed six years ago, but the U.S. Department of Justice has declined to intervene. IBM is confident that our actions are within the letter of the law.”
In particular, Mr. Barlow said that IBM was one of several victims of the hacking campaign carried out by APT 10. APT 10 is a Chinese government-linked group whose members were indicted in 2018, and then-FBI Director Christopher Wray said they targeted “so-and-so” in the global economy. Hackers breached both the company's network and the data it maintains there in partnership with AT&T.
Barlow claimed that intelligence officials from Australia, Canada, New Zealand, the United States and the United Kingdom (the so-called Five Eyes alliance) alerted IBM to the breach in March 2017, and an internal investigation was conducted.
According to the complaint, the investigation concluded that APT 10 may have infiltrated IBM's network more than 56,000 times between 2013 and 2016. Importantly, the company said it could not investigate further because it did not keep logs of basic security practices such as who accessed the network and when.
IBM then allegedly failed to alert authorities or the U.S. government, one of its major customers.
“IBM and AT&T's core networks infrastructure is outdated, allowing hackers to access systems multiple times and move almost anywhere without detection,” the complaint says, noting that an internal IBM investigation concluded that four servers were compromised in the APT 10 hacking campaign.
“The attackers compromised and/or gained access to approximately 400 compromised accounts, totaling approximately 200 systems and servers, across IBM business units, 18 countries, and multiple IBM products,” according to the complaint.
Jason Brown, an attorney representing Barlow, told TechCrunch that his office “looks forward to aggressively litigating this matter.”
“You can't sell cybersecurity to the federal government while allegedly having security problems within your own company,” Brown said.
Barlow said other breaches he was aware of also affected Trusteer, a cybersecurity startup acquired by IBM in 2013 and breached in 2018, he said. Another is Truven, a healthcare data startup that IBM acquired in 2016, but he said it was breached multiple times after the acquisition.
In both cases, Barlow accused IBM of failing to properly investigate and disclose these breaches.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

