Monday, August 3, 2026

Policy & Regulation

IBM accused of covering up multiple data breaches

A former IBM executive alleges the company potentially covered up multiple data breaches by foreign state actors, including a massive hacking campaign by APT 10.

IBM accused of covering up multiple data breaches

William Barlow, a former IBM cybersecurity executive and whistleblower, has filed a lawsuit alleging that the technology corporation was hacked three times in the previous decade by foreign governments. The lawsuit, which was filed in 2020, claims that IBM subsequently engaged in covering up the data breaches rather than disclosing them. Barlow, who served as IBM’s vice president of threat intelligence until August 2019, alleged in the complaint that the company’s core network was routinely hacked by foreign state actors and others, with data frequently stolen without government agencies being notified.

The complaint details a specific campaign by APT 10, a Chinese government-linked hacking group. According to an internal IBM report cited in the lawsuit, the group potentially breached IBM’s network more than 56,000 times between 2013 and 2016. The report also noted that IBM failed to keep logs of network access, which prevented further investigation. The internal document stated: “The attackers have compromised and/or accessed nearly 400 compromised accounts and almost 200 total systems and servers across every IBM business unit, eighteen countries, and multiple IBM products.” The complaint further alleges that because the core network infrastructure maintained in partnership with AT&T was archaic, hackers were able to gain access on numerous occasions and roam undetected.

IBM has declined to address the specific accusations. IBM spokesperson Miki Carver stated that the complaint was filed six years ago, the U.S. Department of Justice declined to intervene, and the company is confident its actions followed the letter of the law. Meanwhile, Jason Brown, a lawyer representing Barlow, argued that a company cannot sell cybersecurity to the federal government while allegedly having these security problems within its own company.

The lawsuit also alleges that IBM failed to properly investigate and disclose security incidents at its acquired subsidiaries. Specifically, Barlow claims that Trusteer, a cybersecurity startup acquired by IBM, was breached in 2018. Additionally, Truven, a healthcare data startup acquired by IBM, was breached multiple times after its acquisition. The complaint notes that in March 2017, the Five Eyes—an intelligence alliance of Australia, Canada, New Zealand, United States, and the United Kingdom—warned IBM of the APT 10 breach, which prompted the company’s internal investigation.

Why it matters

IBM is a major cybersecurity vendor to the U.S. federal government, which makes the alleged concealment of data breaches especially significant.