
A former senior cybersecurity executive at IBM has leveled serious accusations against the tech giant, claiming that the company experienced significant hacking incidents over the past decade, allegedly orchestrated by foreign governments, and subsequently concealed them. In a lawsuit that came to light this week, William Barlow, who served as IBM's vice president of threat intelligence until mid-2019, asserts that the company identified breaches by Chinese hackers in its core network between 2013 and 2016 but failed to disclose these incidents. Barlow's allegations extend beyond the core network, stating that at least two subsidiaries of IBM also experienced data breaches that were not reported. He claims that IBM’s core network was regularly targeted by state-sponsored hackers and that sensitive data was routinely stolen without notifying relevant government authorities. This revelation underscores a concerning trend: major tech firms, including IBM, sometimes opt not to inform the public or governmental bodies about significant cyberattacks. Given IBM's role as a primary cybersecurity provider for the U.S. federal government, the implications of these alleged cover-ups are particularly alarming. In response to the claims, IBM spokesperson Miki Carver refrained from addressing specific questions regarding the lawsuit but emphasized that the U.S. Department of Justice had declined to intervene, asserting IBM's compliance with legal standards. Barlow's complaint highlights IBM as a victim of a hacking campaign executed by APT 10, a group linked to the Chinese government. This group was notably mentioned by former FBI Director Christopher Wray in 2018 as targeting a wide range of global enterprises. The breach reportedly affected both IBM’s network and its data in collaboration with AT&T. The complaint details that in March 2017, a coalition of intelligence officials from the Five Eyes alliance—comprising Australia, Canada, New Zealand, the U.S., and the U.K.—alerted IBM about the breaches, triggering an internal investigation. Findings from this investigation revealed that APT 10 had potentially compromised IBM’s network over 56,000 times during the specified period. Alarmingly, IBM claimed it could not conduct a thorough investigation due to a lack of logs to track network access, a fundamental security oversight. The internal investigation reportedly found that four servers were compromised during the APT 10 campaign, with nearly 400 accounts and approximately 200 systems across multiple IBM business units and countries being accessed by the attackers. Jason Brown, Barlow's attorney, expressed determination to pursue the case vigorously, asserting that it is contradictory for IBM to market its cybersecurity services to the federal government while allegedly facing such significant security vulnerabilities within its own operations. Additionally, Barlow noted other breaches related to Trusteer, a cybersecurity firm acquired by IBM in 2013, which he claims was breached in 2018, and Truven, a healthcare data company bought by IBM in 2016, which reportedly suffered multiple breaches post-acquisition. In both instances, Barlow argues that IBM failed to adequately investigate or disclose these incidents.
Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...
TechCrunch | Jul 25, 2026, 19:50
In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...
CNBC | Jul 25, 2026, 12:15
In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...
Business Insider | Jul 25, 2026, 13:10Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...
CNBC | Jul 25, 2026, 05:15
Prentis, a newly established AI research lab, is making waves in the tech industry as it prepares to raise $100 million ...
TechCrunch | Jul 25, 2026, 24:00