GCIS CYBERSECURITY BRIEFING: RSA SecurID Theft Spawns Speculation on Potential Attack Scenarios

ISSUED BY: GCIS Communications Command Center

SOURCE: EWeek

22March2011 4:30amEST

GCIS CYBERSECURITY UPDATE:  The network of one the world’s largest and trusted security firms has been breached, and an unknown amount of information about its popular multifactor authentication technology has been stolen. Customers are worried about what form potential attacks could take.

Cyber breachThe SecurID information that was stolen would not allow attackers to launch a successful direct attack on existing SecureID customers, Art Coviello, executive chairman of RSA Security, wrote in an open letter to customers posted on the company’s Website March 17. However, the company acknowledged the information could be potentially used to “reduce the effectiveness” of an existing SecurID deployment as part of a broader attack.

With RSA keeping mum about what exactly was stolen, when the data breach occurred, how attackers got into the network and how long the breach lasted, security experts can more or less give their imaginations free reign to suggest potential attack scenarios.

Adam Vincent, CTO of the Public Sector group at Layer 7 Technologies, wondered about the implications of a broader attack hinted at by Coviello. “Reading between the lines,” RSA made it sound as if the data theft made RSA SecureID ineffective without needing to compromise any specific usernames or passwords, Vincent told eWEEK.

The “well-organized group” of hackers behind this targeted attack would have to complete “many steps” to successfully attack an organization using SecurID tokens for authentication, Nick Percoco, senior vice president of SpiderLabs, told eWEEK. While it was “less likely” there will be a direct head-on attack, it wasn’t impossible, he said. (read full report)

"GCIS INTELLIGENCE UPDATE" is an intelligence briefing presented by Griffith Colson Intelligence Service, and provided to the public for informative purposes only. All subject matter is credited to it's source of origin, and is not intended to represent original content authored by GCIS, it's partners or affiliates. All opinions presented are those of the author, and not necessarily those of GCIS or it's partners.