Lockheed Martin Hacked – Rumoured To Be Linked to RSA SecurID Breach

The New Acunetix V12 Engine


You all probably remember the big kerfuffle that occurred after RSA got hacked, it was widely assumed that the SecurID system was compromised somehow and could not be relied on. We reported about it in the article – RSA Silent About Compromise For 7 Days – Assume SecurID Is Broken – where we questioned their silence about the whole thing.

The latest news linked to the above breach is that Lockheed Martin has been compromised and it could possibly be linked to the SecurID tokens. Now this is a BIG deal as they are a US Military contractor and probably have some pretty juicy secrets in their network.

Lockheed Martin Saturday night acknowledged that it its information systems network had been the target of a “significant and tenacious attack,” but said that its security team detected the intrusion “almost immediately and took aggressive actions to protect all systems and data.”

No data from customers, programs or employees was compromised, the top U.S. defense contractor said in a brief statement.

The company said that it has kept U.S. government agencies informed of its investigation as it “continues to work around the clock to restore employee access to the network.”

The attack was first reported last Thursday by Reuters, which cited a defense official and two unnamed sources familiar with the situation. The news agency reported that the cyberattack was affecting many employees at Lockheed Martin, which is based in Bethesda, Maryland, and makes fighter planes and other weapons systems.

Bruce Schneier mentioned it here – Lockheed Martin Hack Linked to RSA’s SecurID Breach

And a lot of people have been sayings it’s just speculation, yah the hack is real – but does it have anything to do with SecurID really? We have no idea.

There’s some interesting thoughts on it here – Weekly Intelligence Summary:2011-05-27


On Saturday, an official with the U.S. Department of Homeland Security confirmed the attack to the news agency. However, Lockheed Martin continued to decline comment.

The intrusion reported involves the use of RSA SecurID tokens, used by Lockheed Martin employees to access the company network remotely. Security analysts have urged that companies using the tokens review authentication procedures.

Lockheed Martin did not divulge how its systems were attacked. The company faces “constant threats from adversaries around the world” and regularly acts to heighten security of its systems, it said in the statement.

Homeland Security have confirmed the compromise but as of now, Lockheed Martin has no made statement regarding what has happened or what data has been accessed.

There some thoughts from SANS ISC Diary here on how to stay secure even if you do use SecurID – Lockheed Martin and RSA Tokens.

It’ll be interesting to see what other news comes out about this and if any actual details are revealed. We shall be keeping an eye on it.

Source: Network World

Posted in: Cryptography, Exploits/Vulnerabilities, Legal Issues

, , , ,


Latest Posts:


airgeddon - Wireless Security Auditing Script airgeddon – Wireless Security Auditing Script
Airgeddon is a Bash powered multi-use Wireless Security Auditing Script for Linux systems with an extremely extensive feature list.
Acunetix v12 - Pause & Resume Acunetix v12 – More Comprehensive More Accurate & 2x Faster
Acunetix, the pioneer in automated web application security software, has announced the release of Acunetix v12 - more comprehensive, accurate & 2x faster.
CloudFrunt - Identify Misconfigured CloudFront Domains CloudFrunt – Identify Misconfigured CloudFront Domains
CloudFrunt is a Python-based tool for identifying misconfigured CloudFront domains, it uses DNS and looks for CNAMEs which may be allowed to be associated with CloudFront distributions.
Airbash - Fully Automated WPA PSK Handshake Capture Script Airbash – Fully Automated WPA PSK Handshake Capture Script
Airbash is a POSIX-compliant, fully automated WPA PSK handshake capture script aimed at penetration testing, it is compatible with Bash and Android Shell.
XXEinjector - Automatic XXE Injection Tool For Exploitation XXEinjector – Automatic XXE Injection Tool For Exploitation
XXEinjector is an XXE Injection Tool that automates retrieving files using direct and out of band methods. Directory listing only works in Java applications.
Yahoo! Fined 35 Million USD For Late Disclosure Of Hack Yahoo! Fined 35 Million USD For Late Disclosure Of Hack
Ah Yahoo! in trouble again, this time the news is Yahoo! fined for 35 million USD by the SEC for the 2 year delayed disclosure of the massive hack, we actually reported on the incident in 2016 when it became public.


Comments are closed.