Cisco Settlement Over Hackable Technology a Warning to Government Contractors

The Cisco bug was in surveillance software that ended up in schools, hospitals, airports, and prisons.

Advertisement
By Joseph Marks, The Washington Post | Updated: 2 August 2019 10:31 IST

The $8.6 million (roughly Rs.59 crores) settlement Cisco will pay to settle claims it sold states and federal agencies hackable surveillance software marks a sea change in how seriously the government is now taking cyber-security bugs.

The Cisco bug, which a whistleblower first alerted the company about in 2008, was in surveillance software that ended up in schools, hospitals, airports and prisons as well as federal agencies and at least 15 state governments, as I reported yesterday.

It could have allowed hackers to spy on surveillance video footage, turn cameras on and off and delete footage. It could even have allowed those hackers to compromise other connected physical security systems such as alarms or locks. Yet the company didn't fix the bug until 2012 - one year after the whistleblower, James Glenn, filed a lawsuit against the company.

Advertisement

The settlement marks the first time a company has been forced to pay out for inadequate cyber-security protections under a federal whistleblower law that normally targets fraud and graft in federal contracts. And it's sure to prompt other government suppliers to take a closer look at the security of the products they sell to the US government.

The federal government is reviewing its multibillion-dollar contracting enterprise, which supplies everything from military hardware to border surveillance tools but which officials have said was not designed to make cyber-security a major consideration.

Those officials worry that federal agencies are inadvertently greenlighting a slew of hackable products for purchase by federal agencies - many of which are then also bought by states and government grant recipients such as schools and hospitals. The flawed Cisco software could be a prime example: Glenn's lawyers say it was purchased by the US Secret Service, the Federal Emergency Management Agency and military services as well as prisons and police departments, including the New York Police Department.

Advertisement

Even Cisco says the settlement underscores how government is taking cyber-security in the products it buys far more seriously than it used to. In a blog post yesterday, Cisco's Chief Legal Officer Mark Chandler described the settlement as an example of "changing standards" and noted that "what seemed reasonable at one point no longer meets the needs of our stakeholders today."

"We intend to stay ahead of what the world is willing to accept," Chandler added.

Advertisement

Glenn was working for a Cisco subcontractor called NetDesign in Denmark when he first spotted the cyber-security bug and he sent the company numerous "detailed reports" throughout 2008 "revealing that anyone with a moderate grasp of network security could exploit this software," his lawyers told me. But Glenn never got a response, his attorneys said.

"I was very concerned about the possibility that someone might endanger public safety by hacking into government systems," Glenn said in a statement.

Advertisement

Glenn filed his lawsuit under the False Claims Act, which effectively allows individuals to sue on behalf of the government if they believe a government contractor is committing fraud. The government can join the suit later and collect most of the proceeds.

In this case, the federal government and state governments that joined the suit will collect 80 percent of the $8.6 million award while Glenn and his attorneys will take 20 percent, his lawyers said.

States that joined the settlement with the Justice Department include New York, California, Illinois, Florida, Massachusetts and Virginia.

© The Washington Post 2019

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Cisco
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S24 Ultra vs iPhone 16 Pro: Amazon, Flipkart Deals Compared
  2. iQOO 15 Design Revealed; Could Come in These New Colourways
  3. Motorola's Festive Bet: Value Over Gimmicks
  4. Nothing Ear Open Goes on Sale in India During Flipkart's Sale at This Price
  5. Xiaomi 17, 17 Pro, 17 Pro Max Will Launch in China on This Date
  6. Vivo X300 Series Will Make Its China Debut on October 13: All the Details
  7. Amazon, Flipkart Sale: Deals on iPhone 16 Pro, iPhone 15, and iPhone 14
  8. Samsung Galaxy S24 FE Gets Android 16-Based One UI 8: Here's How to Update
  9. Samsung Galaxy S26 Ultra's 'Private Display' Feature Spotted on One UI 8.5
  10. Amazon Great Sale 2025 Live Updates: Deals on iPhone 15, OnePlus 13 and More
  1. WhatsApp for Android Said to Be Testing Feature Which Lets Users Mute ‘Everyone’ Mentions in Group Chats
  2. Nothing Ear Open Goes on Sale in India During the Flipkart Big Billion Days Sale: Price, Specifications
  3. Sony Launches 'Festive Sale', Slashes PS5 Price in India by Rs. 5,000
  4. Samsung Galaxy S24 FE Reportedly Receives Stable One UI 8 Update: How to Download and Install
  5. Samsung Galaxy S24, Galaxy Z Fold 6, and Z Flip 6 Start Receiving One UI 8 Update in South Korea
  6. Lenovo Cancels Some Pre-Orders of Lenovo Legion Go 2, Says Demand 'Substantially Exceeded' Projections
  7. iQOO 15 Design, New Colourways Revealed Ahead of October Launch
  8. Oppo Find X9 Launch Date Announced, Global Debut Teased; Will Feature Dimensity 9500 Chipset, Up to 7,500mAh Battery
  9. OpenAI, Jony Ive Reportedly Developing AI Speakers and Smart Glasses on the Back of Apple’s Supply Chain
  10. HyperOS 3 Update Release Timeline Revealed; Xiaomi 15 Ultra, Redmi K80 Pro Among First Phones to Get Updates
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.