EMC's anti-hacking division hacked

Advertisement
By Associated Press | Updated: 11 June 2012 15:02 IST
Highlights
  • The world's biggest maker of data storage computers on Thursday said that its security division has been hacked.
The world's biggest maker of data storage computers on Thursday said that its security division has been hacked, and that the intruders compromised a widely used technology for preventing computer break-ins.

The breach is an embarrassment for EMC Corp., also a premier security vendor, and potentially threatens highly sensitive computer systems.

The incident is a rare public acknowledgement by a security company that its internal anti-hacking technologies have been hacked. It is especially troubling because the technology sold by EMC's security division, RSA, plays an important role in making sure unauthorized people aren't allowed to log into heavily guarded networks.

The scope of the attack wasn't immediately known, but the potential fallout could be widespread. RSA's customers include the military, governments, various banks and medical facilities and health insurance outfits. EMC, which is based Hopkinton, Mass., itself is an RSA customer.

EMC said in a filing with the Securities and Exchange Commission that RSA was the victim of what is known as an "advanced persistent threat," industry jargon for a sophisticated computer attack. The term is often associated with corporate espionage, nation-state attacks, or high-level cybercriminal gangs.

EMC didn't offer clues about the suspected origin of the attack. It said it recently discovered an "extremely sophisticated" attack in progress against its networks and discovered that the infiltrators had made off with confidential data on RSA's SecurID products. The technology underpins the ubiquitous RSA-branded keychain "dongles" and other products that blanket important computer networks with an additional layer of protection.

The products make it harder for someone to break into a computer even if a password is stolen, for example. The RSA device, working in concert with back-end software, generates an additional password that only the holder of the device would know. But if a criminal can figure out how those additional passwords are generated, the system is at risk.

RSA is one of the best-known names for this type of "two-factor authentication" technology.
RSA declined to comment on what type, or how much, information was stolen.

Richard Stiennon, a security analyst with the IT-Harvest firm, said there would be "tremendous repercussions" if the criminals were able to silently tap into critical systems using the stolen information.

"You'd never have a sign that you've been breached," he said.

In its SEC filing, RSA said that it is "confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers." However, it warned that "this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack."

"We have no evidence that customer security related to other RSA products has been similarly impacted," said the company's executive chairman, Art Coviello. "We are also confident that no other EMC products were impacted by this attack. It is important to note that we do not believe that either customer or employee personally identifiable information was compromised as a result of this incident."

The company said it is providing "immediate remediation steps" for customers. It didn't specify what those are. It outlined some generic security tips that offer clues about how its customers might be targeted with the information stolen from RSA, such as closely monitoring the use of social networking websites by people with access to critical networks and the need to educate employees on the danger of clicking on links or attachments in suspicious e-mails.

EMC said it doesn't expect the breach to have a meaningful impact on its financial results.
Its shares slipped 8 cents to $25.58 in extended trading Thursday. They ended the regular session up 25 cents at $25.56.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: EMC corp, Hacking, Security Breach
Advertisement
Popular Mobile Brands
  1. iPhone 17 Air Battery Specifications, Weight and Other Details Leaked
  2. Nothing Phone 3 Design Teaser Shows Textured Button
  3. CMF Phone 2 Pro Review: A Perfect Blend of Style and Speed
  4. Motorola Edge 2025 Goes Official With New AI Key: See Price, Features
  5. DeepSeek Unveils Update to R1 Model as AI Race Heats Up
  6. Astronomers Spot Nearly Perfect Supernova Remnant of Unknown Size and Distance
  1. Astronomers Spot Nearly Perfect Supernova Remnant of Unknown Size and Distance
  2. Strange Planet Confirmed in Binary Star System Nu Octantis
  3. Clair Obscur: Expedition 33 Has Fittingly Sold 3.3 Million Copies in 33 Days
  4. Luxembourg Labels Crypto Firms as High-Risk Entities for Money Laundering 
  5. Opera Neon Agentic Browser Unveiled, Uses AI Agents to Plan Trips and Build Websites
  6. Samsung Galaxy Z Fold 7 Spotted on Geekbench Again; Key Specifications Listed
  7. Nothing Phone 3 Design Officially Teased; Appears With Textured Button
  8. Xiaomi Reports Rs. 1.31 Lakh Crore Revenue in Q1 2025, Beats Rs. 1.2 Lakh Crore Mark Again
  9. Samsung Galaxy S26 Series to Use Inkjet Printing to Enable Thinner Lens Modules: Report
  10. iOS 19 to Reportedly Enable Easy eSIM Transfers from iPhone to Android
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.