RSA servers hacked as SecurID data stolen
As RSA has its servers hacked, its two-factor authentication customers will no doubt be highly concerned.


RSA - the security arm of EMC - has admitted to having a number of its servers hacked, as data on its two-factor authentication product SecurID was compromised.
The firm warned the data could be used to "reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack," and RSA urged customers to take immediate remedial action.
RSA executive chairman Art Coviello said the firm's security systems had been targeted by an "extremely sophisticated cyber attack."
It is believed the attack was in the Advanced Persistent Threat (APT) category, which may indicate a well-funded group of individuals were responsible.
APTs involve significant intelligence research and the use of numerous techniques to hack targets. They need serious investment to be carried out.
RSA is now in the process of informing customers about the dangers and how to strengthen SecurID implementations.
"We have no evidence that customer security related to other RSA products has been similarly impacted," Coviello said in an open letter to customers.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We are also confident that no other EMC products were impacted by this attack. It is important to note that we do not believe that either customer or employee personally identifiable information was compromised as a result of this incident."
In an advice note to customers, RSA listed a number of recommendations for customers to follow, with the first point being to increase focus on security for social media applications and the use of them by anyone with access to critical networks.
RSA has a wide range of customers, ranging from high profile private companies to government bodies.
A sad day'
The breach will be damaging for RSA and it could take some time for the EMC division to recover, said SecurEnvoy co-founder Steve Watts.
Watts said it was a "sad day" to see a company with the reputation of RSA being hit by such a significant attack.
"Anyone with an RSA token doesn't know if they're going to be compromised. The industry is a bit concerned," Watts told IT PRO.
"This isn't just a bit of a marketing booboo, this is a major strategic issue. The problem is that it will take quite a long time to get over it."
If RSA has to initiate a recall of a large chunk of its tokens, then this would lump the firm with a costly logistical nightmare, Watts added.
"Is it going to be as extreme as changing every token that is sent out into the marketplace? Is it as far as to send out replacement tokens for every user? That's just beyond measure," Watts added.
Earlier this week, Jim Fulton, vice president at DigitalPersona, told IT PRO many companies were struggling with token deployments as it was.
"I've heard people say that if they could, they'd throw them underneath a lorry and crush them because they hate them so much," Fulton said.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
How secure is Gmail?
Tutorials The practical steps you should take to secure your Gmail account, from implementing 2FA to performing regular checkups
By Davey Winder
-
New MFA security standards for online payments come into force
News Version 4.0 of PCI DSS also reforms password requirements and broadens its terminology to address other network access controls
By Danny Bradbury
-
HornetSecurity 365 Total Protection review: Keeping email squeaky clean
Reviews Tough email protection for Microsoft 365 that’s simple to deploy, easy to manage and very affordable
By Dave Mitchell
-
Google will auto-enrol 150 million users in 2FA by end of 2021
News An additional two million YouTube creators will also be required to switch it on the 2SV feature by the end of the year
By Sabina Weston
-
2FA bypass flaw on cPanel threatens the security of 70 million domains
News Hackers were able to try as many 2FA codes as they wanted using brute force methods before landing on the right one
By Keumars Afifi-Sabet
-
Your first step researching Managed File Transfer
Whitepapers Advice and expertise on researching the right MFT solution for your business
By ITPro
-
What is Strong Customer Authentication (SCA) under PSD2?
In-depth An in-depth look at the EU directive that aims to harmonise online payment protection
By Dale Walker
-
Dell EMC Networking Z9264F-ON review: A 64-port powerhouse
Reviews Are you ready for 100-Gigabit Ethernet? Dell EMC’s Z9264F-ON certainly is
By Dave Mitchell