A newly unsealed 2020 lawsuit reveals that former IBM cybersecurity executive William Barlow has accused the tech giant of concealing three major state-sponsored cyber-attacks on its networks between 2013 and 2019.
A history of hidden security breaches
Barlow, who served as IBM’s vice president of threat intelligence until August 2019, filed the complaint in 2020, which was unsealed this week. The suit alleges that IBM discovered Chinese state-backed hackers had breached its core network between 2013 and 2016, but chose to cover up the intrusions rather than disclose them. Furthermore, Barlow claims that at least two of IBM’s recently acquired subsidiaries suffered similar breaches that were also actively concealed.
According to the court documents, IBM’s core network was “routinely hacked by foreign state actors and others.” The lawsuit states that sensitive data was frequently exfiltrated, yet relevant government agencies were never notified of these security failures.
Although the alleged incidents occurred over a decade ago, the disclosure highlights a persistent issue in the tech industry: major public corporations, including prominent cybersecurity vendors like IBM, failing to report critical breaches to the public or government regulators. As a primary technology partner for the US federal government, IBM’s alleged non-disclosure is highly significant, particularly given the raft of strict data breach notification laws introduced globally in recent years to combat this lack of transparency.
The legal action was first reported on the lawsuit by Bloomberg.
The scale of the APT 10 intrusion
The complaint specifically names APT 10, a notorious hacking collective linked to the Chinese government, as the group behind the primary intrusion. In 2018, FBI Director Christopher Wray described the group’s targets as a “Who’s Who” of the global economy following formal indictments. The hackers reportedly compromised both IBM’s proprietary network and the shared data infrastructure it managed in partnership with telecoms giant AT&T.
var playerInstance_jwplayer_6a7a0bc165aea = jwplayer( “jwplayer_6a7a0bc165aea” );
playerInstance_jwplayer_6a7a0bc165aea.setup({
playlist: “https://cdn.jwplayer.com/v2/media/lv0GaEwB”,
});
Barlow claims that the Five Eyes intelligence alliance—comprising authorities from the UK, US, Australia, Canada, and New Zealand—warned IBM about the compromise in March 2017. This warning subsequently triggered an internal investigation by the company.
That internal probe concluded that APT 10 had potentially accessed IBM’s network more than 56,000 times between 2013 and 2016. Crucially, the investigation was severely limited because IBM had failed to maintain basic network access logs—a fundamental industry security practice—preventing investigators from determining the full extent of the data exfiltration.
“Archaic” systems and compromised accounts
The lawsuit paints a damning picture of the company’s IT infrastructure, stating that because “IBM and AT&T’s Core Networks’ infrastructure is archaic, hackers have been able to gain access to the system on numerous occasions and can roam almost anywhere undetected.” The internal investigation ultimately confirmed that at least four major servers were fully compromised during the APT 10 campaign.
An internal IBM report cited in the complaint revealed the vast scale of the breach: “The attackers have compromised and/or accessed nearly 400 compromised accounts and almost 200 total systems and servers across every IBM business unit, eighteen countries, and multiple IBM products.” Despite these findings, no official notifications were sent to corporate clients or government departments.
Subsidiaries targeted and silenced
The security failures allegedly extended to IBM’s acquisitions. Barlow pointed to Trusteer, a cybersecurity startup purchased by IBM in 2013, which was reportedly breached in 2018. Similarly, Truven, a healthcare data specialist acquired in 2016, allegedly suffered multiple security breaches post-acquisition. In both instances, Barlow claims IBM failed to conduct proper investigations or disclose the incidents to affected parties.
IBM’s defence and the legal battle ahead
When approached for comment, IBM spokesperson Miki Carver declined to address the specific allegations or the details of the lawsuit. Instead, Carver stated: “This complaint was filed six years ago, and the U.S. Department of Justice declined to intervene. IBM is confident that our actions followed the letter of the law.”
However, Barlow’s legal team remains resolute. Jason Brown, the lawyer representing the whistleblower, confirmed they are preparing for a robust court battle. Brown emphasised the hypocrisy of the situation, noting that a company cannot ethically market cybersecurity solutions to federal governments whilst allegedly concealing severe, unresolved security vulnerabilities within its own corporate infrastructure.
