Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
IBM

IBM Vendor Cyber Rating & Cyber Score

ibm.com

At IBM, we do more than work. We create. We create as technologists, developers, and engineers. We create with our partners. We create with our competitors. If you're searching for ways to make the world work better through technology and infrastructure, software and consulting, then we want to work with you. We're here to help every creator turn their "what if" into what is. Let's create something that will change everything.


IBM A.I CyberSecurity Scoring

IBM
Company Information
Website:http://www.ibm.com
Employees number:336,062
Number of followers:19,659,540
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:ibm.com
IBM Risk Score (AI oriented)
Between 0 and 549
logo
IBMIT Services and IT Consulting
Updated:
04/08/2026
403/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
IBM Global Score (TPRM)
xxxx
logo
IBMIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

IBM
IBMCritical
Current Score
403C (CRITICAL)
01000
28 incidents
-29.91 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
403Before Incident
JULY 2026
495Before Incident
Breach
01 Jul 2026IBM
IBM: Business Matters: IBM says corporate data breach costs hit record high | Watch News Videos Online

Canadian Data Breaches Hit Record Costs as Attacks Grow in Scale and Duration

400After Incident
HIGH-95
IBM1785357547
IBM Report: Canadian Data Breaches Hit Record Costs as Attacks Grow in Scale and Duration A new report from IBM reveals that data breaches are inflicting increasingly severe financial damage on Canadian organizations, with the average cost surging to $7.11 million a rise driven by larger-scale attacks and prolonged containment efforts. The findings, released in late July 2026, highlight a growing trend of cyber incidents becoming more complex and costly for businesses. While the report does not specify individual breaches, it underscores the broader economic impact of cyber threats on Canadian enterprises, including extended recovery timelines and heightened operational disruptions. The data arrives amid rising global cybersecurity concerns, with organizations facing evolving attack vectors and regulatory pressures. The report serves as a benchmark for the financial toll of cyber incidents in Canada, reflecting both direct costs such as incident response and legal fees and indirect consequences like reputational harm and lost business. No specific sectors or companies were named, but the findings signal a need for heightened cyber resilience across industries. The report’s release coincides with other economic developments, including new U.S. tariffs on Canadian goods and ongoing labor disputes, further complicating the business landscape.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $7.11 million (average)Operational Impact: Extended recovery timelines and heightened operational disruptionsBrand Reputation Impact: Reputational harm
Breach
01 Jul 2026IBM
IBM: IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average

AI-Enabled Breaches Surge, Costing Companies $6 Million on Average

400After Incident
CRITICAL-95
IBM1785321873
AI-Enabled Breaches Surge, Costing Companies $6 Million on Average: IBM Report A new study from IBM reveals that one in four malicious data breaches in 2025 were AI-enabled, marking a 56% increase from the previous year. These breaches carried a steep financial toll, averaging $6 million per incident nearly $1 million higher than the global breach average of $4.99 million. The IBM 2026 Cost of a Data Breach Report highlights a growing threat landscape, with over 20% of organizations reporting breaches targeting AI models or applications. The findings underscore the rapid adoption of AI by cybercriminals, who are leveraging the technology to enhance attack sophistication, speed, and evasion tactics. While the report does not specify regional breakdowns, the data reflects a global trend, with AI-driven attacks becoming a key driver of financial and operational risk for businesses. The surge in AI-enabled breaches signals an urgent shift in cybersecurity strategies as organizations grapple with defending against increasingly automated and adaptive threats.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $6 million per incidentSystems Affected: AI models or applications
Cyber Attack
01 Jul 2026IBM
IBM: The Cost of Getting Hacked in India Just Hit a Record High. AI is One Big Reason

AI-Driven Cyberattacks Push India’s Data Breach Costs to Record ₹25.5 Crore in 2026

400After Incident
CRITICAL-95
IBM1785746071
AI-Driven Cyberattacks Push India’s Data Breach Costs to Record ₹25.5 Crore in 2026 India’s cybersecurity landscape is facing unprecedented challenges as the average cost of a data breach surged to a record ₹25.5 crore in 2026, marking a 16% increase from the previous year, according to IBM’s 2026 Cost of a Data Breach Report. The rise is largely attributed to the growing sophistication of AI-powered cyberattacks, which accounted for 26% of malicious breaches in the country. Cybercriminals are leveraging AI to launch faster, more scalable, and highly targeted attacks, with phishing including email, voice, and SMS scams remaining the most common entry point, responsible for 19% of all breaches. Other prominent attack vectors include drive-by compromises and supply-chain attacks. The financial impact of breaches varies sharply based on an organization’s cybersecurity posture. Companies with extensive AI and security automation reported average breach costs of ₹21.3 crore, while those without such systems faced losses of ₹31.6 crore a 48% higher financial burden. Despite this, AI adoption in cybersecurity remains uneven: only 32% of organizations have deployed AI-driven security measures, while an equal proportion have no meaningful adoption at all. Proactive measures such as red teaming and penetration testing proved effective, reducing average breach costs by ₹2.47 crore. Following incidents, 74% of organizations plan to increase investments in incident response, threat detection, identity management, AI security, and employee awareness. The financial services sector suffered the highest average breach cost at ₹40.9 crore, followed by technology (₹35.7 crore) and communications (₹34.5 crore), reflecting the elevated risks for industries handling large volumes of sensitive data. The report also noted that the average breach exposed nearly 39,500 records, the highest on record. As AI reshapes both defensive and offensive cybersecurity strategies, the gap between organizations that embrace automation and those that lag behind continues to widen, with significant financial consequences.
INCIDENT DETAILS -
TYPE
data_breachAI-powered cyberattack
IMPACT
Financial Loss: ₹25.5 crore (average)Data Compromised: 39,500 records (average)
DATA BREACH
Type Of Data Compromised: sensitive dataNumber Of Records Exposed: 39,500 (average)
JUNE 2026
515Before Incident
Breach
11 Jun 2026IBM
AT&T and IBM: IBM Whistleblower Claims Data Breach Cover-Up

IBM Whistleblower Allegations Over Alleged Breach Cover-Ups

486After Incident
CRITICAL-29
ATTIBM1781168591
IBM Faces Whistleblower Allegations Over Alleged Breach Cover-Ups IBM is embroiled in a cybersecurity controversy following a whistleblower lawsuit filed by William Barlow, its former vice president of threat intelligence. Barlow alleges the tech giant concealed multiple data breaches, including attacks linked to foreign state actors, while providing security assurances to government clients. The lawsuit claims IBM’s core network was "routinely hacked" by foreign and unidentified hackers, with senior leadership allegedly pressuring teams to downplay internal findings and avoid full disclosure. The complaint also implicates AT&T, which operated a cloud system called Core Network on IBM’s behalf, serving parts of the U.S. federal government. According to the filing, both companies allegedly failed to properly notify government clients of breaches, potentially leaving sensitive data exposed. The case highlights broader concerns about breach transparency, particularly for vendors handling critical infrastructure. If proven, the allegations could erode trust in enterprise cybersecurity practices, as delayed disclosures give attackers more time to exploit vulnerabilities. The lawsuit also raises questions about vendor accountability, especially for companies managing government contracts where sensitive data including military, employee, and citizen information is at stake. While the allegations remain unproven, the case underscores the risks of supply-chain attacks, where hackers target vendors to access multiple clients. For businesses relying on third-party providers, the incident serves as a reminder to scrutinize breach-notification terms in contracts, ensuring clear protocols for incident reporting and response. The lawsuit is pending, with IBM and AT&T yet to formally respond in court. The outcome could set a precedent for how major tech firms handle breach disclosures, particularly when government clients are involved.
INCIDENT DETAILS -
TYPE
Data BreachSupply-Chain Attack
MOTIVATION
EspionageData Exfiltration
IMPACT
Data Compromised: Sensitive data including military, employee, and citizen informationIBM’s core networkAT&T’s Core Network cloud systemBrand Reputation Impact: Erosion of trust in enterprise cybersecurity practices
DATA BREACH
Military dataEmployee dataCitizen informationSensitivity Of Data: HighPersonally Identifiable Information: Yes
MAY 2026
511Before Incident
APRIL 2026
506Before Incident
Vulnerability
20 Apr 2026IBM
Anthropic, Flowise, DocsGPT and IBM: Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters

Critical AI Framework Vulnerability Exposes Millions to Remote Code Execution

504After Incident
CRITICAL-2
ANTARCFLOIBM1776659058
Critical AI Framework Vulnerability Exposes Millions to Remote Code Execution Researchers at OX Security have uncovered a severe architectural flaw in the Model Context Protocol (MCP), a communication standard developed by Anthropic and embedded in AI frameworks across Python, TypeScript, Java, and Rust. The vulnerability enables remote code execution (RCE), exposing sensitive data including API keys, internal databases, and chat histories across the AI supply chain. The flaw affects Flowise, a widely used open-source AI workflow builder, and extends to over 200,000 vulnerable instances, with 150 million downloads and 7,000 publicly accessible servers at risk. During testing, OX Security successfully executed live commands on six production platforms, demonstrating the flaw’s real-world impact. Key Exploitation Vectors Identified: - Unauthenticated UI injection in major AI frameworks. - Hardening bypasses in "protected" environments like Flowise. - Zero-click prompt injection in AI IDEs (e.g., Windsurf, Cursor). - Malicious MCP server distribution, with 9 out of 11 registries compromised in testing. At least ten CVEs have been issued, covering critical vulnerabilities in platforms such as LiteLLM, LangChain, GPT Researcher, DocsGPT, and IBM’s LangFlow. Despite OX Security’s recommendations for root-level patches, Anthropic declined to implement protocol-wide fixes, describing the behavior as "expected." The company did not oppose the public disclosure of the findings. The incident underscores systemic risks in AI infrastructure, with the flaw inherited by any developer building on MCP expanding the attack surface across the ecosystem. Security teams are advised to restrict public exposure of AI services, treat MCP inputs as untrusted, and enforce sandboxed environments. Patches for affected platforms are now available.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
API keysInternal databasesChat historiesSystems Affected: AI frameworks (Python, TypeScript, Java, Rust), Flowise, LiteLLM, LangChain, GPT Researcher, DocsGPT, IBM’s LangFlowOperational Impact: Exposure of sensitive data and potential remote code execution across AI supply chainBrand Reputation Impact: Systemic risks in AI infrastructure highlighted
DATA BREACH
API keysInternal databasesChat historiesSensitivity Of Data: High
APRIL 2026
511Before Incident
Cyber Attack
01 Apr 2026IBM
IBM Italy and Sistemi Informativi: Salt Typhoon breach IBM subsidiary in Italy: a warning for Europe’s digital defenses

Chinese-Linked APT Group Salt Typhoon Suspected in IBM Italy Subsidiary Breach

502After Incident
CRITICAL-9
SIS1777847095
Chinese-Linked APT Group Salt Typhoon Suspected in IBM Italy Subsidiary Breach In late April 2026, Italian cybersecurity authorities detected a significant breach at Sistemi Informativi, an IBM Italy subsidiary that manages IT infrastructure for critical public and private institutions. The incident, first reported by La Repubblica, has raised alarms over the expanding reach of Chinese-linked cyber operations in Europe. IBM confirmed the attack, stating it had "identified and contained a cybersecurity incident" and restored affected systems, though details on the breach’s scope remain undisclosed. The company’s website was temporarily taken offline during containment efforts. Multiple intelligence sources suggest the China-associated advanced persistent threat (APT) group Salt Typhoon is behind the attack. If confirmed, this would mark one of the most ambitious cyber intrusions targeting Italy’s public infrastructure in recent years. Active since at least 2019, Salt Typhoon has intensified its operations over the past two years, specializing in supply-chain attacks and zero-day exploits. The group is known for its technical precision, avoiding broad phishing campaigns in favor of infiltrating networks through vulnerabilities in widely used systems, such as Citrix and Cisco. Recent targets include Viasat, Canadian telecom firms, the U.S. Army National Guard, and Dutch government networks all characterized by prolonged data exfiltration and silent reconnaissance. As a key IT provider for Italian institutions, Sistemi Informativi’s compromise could expose sensitive data and critical infrastructure connections, enabling attackers to map and potentially disrupt national digital systems. The breach underscores a growing vulnerability: third-party IT providers serving as high-value targets, where a single compromise can grant access to multiple government and private-sector networks. The incident reflects broader trends in cyber warfare, where state-linked APTs increasingly exploit supply-chain weaknesses and AI-driven tactics to infiltrate critical infrastructure. For Italy and Europe, the attack highlights the need for stronger defenses and enhanced coordination between governments, industry, and intelligence agencies.
INCIDENT DETAILS -
TYPE
Supply-chain attack, Data exfiltration, Reconnaissance
MOTIVATION
Espionage, Critical infrastructure mapping, Data exfiltration
IMPACT
Data Compromised: Sensitive data, Critical infrastructure connectionsSystems Affected: IT infrastructure of public and private institutionsOperational Impact: Temporary website takedown, System restoration effortsBrand Reputation Impact: Potential reputational damage to IBM and Sistemi Informativi
DATA BREACH
Type Of Data Compromised: Sensitive data, Critical infrastructure connectionsSensitivity Of Data: HighData Exfiltration: Yes
MARCH 2026
508Before Incident
FEBRUARY 2026
499Before Incident
JANUARY 2026
566Before Incident
Breach
22 Jan 2026IBM
IBM: Ways to Protect Your Business From a Data Breach

IBM Reports Record-Breaking Data Breach Costs in 2024

496After Incident
LOW-70
IBM1770199486
IBM Reports Record-Breaking Data Breach Costs in 2024, Highlighting Critical Security Gaps In 2024, the average cost of a data breach reached a record $4.88 million, with the healthcare sector facing even steeper losses at $9.8 billion, according to IBM. The rising financial toll underscores the urgent need for robust cybersecurity measures across industries, regardless of business size. Experts emphasize that proactive, layered security is essential to mitigating risks. Key strategies include: - Regularly updating software and security tools (e.g., firewalls, antivirus) to patch vulnerabilities. - Implementing multi-factor authentication (MFA) and strict access controls to limit unauthorized entry. - Securing cloud data through tools like Cloud Access Security Brokers (CASBs), which monitor and block suspicious activity in real time. Notably, businesses not cloud providers are responsible for their own data security under the shared responsibility model. - Frequent data backups (both local and cloud-based) to ensure quick recovery in case of a breach. Human error remains a leading cause of breaches, with 68% of incidents in 2024 involving non-malicious employee actions, per Verizon’s Data Breach Investigations Report. Phishing, weak passwords, and improper data handling are common pitfalls. To combat this, companies are urged to train employees on security protocols, including recognizing phishing attempts and adhering to strict password policies. Advanced protections, once reserved for large enterprises, are now accessible to smaller businesses. Solutions like AI-driven threat detection, continuous monitoring, and MFA are increasingly affordable and effective against evolving cyber threats. As cybercriminals leverage AI and sophisticated hacking techniques, businesses must adopt multi-layered defenses to stay ahead. The article highlights that internal breaches often the hardest to detect pose significant risks, reinforcing the need for ongoing vigilance and adaptive security measures.
INCIDENT DETAILS -
TYPE
data_breach
IMPACT
Financial Loss: $4.88 million (average), $9.8 billion (healthcare sector)
JANUARY 2026
624Before Incident
Breach
01 Jan 2026IBM
IBM: India’s average data breach cost hits record ₹25.5 crore in 2026 as AI-powered attacks rise: IBM

India Faces Record Data Breach Costs as AI Reshapes Cybersecurity Landscape

566After Incident
CRITICAL-58
IBM1785753650
India Faces Record Data Breach Costs as AI Reshapes Cybersecurity Landscape India experienced its highest-ever average cost of a data breach in 2026, with organizations losing ₹25.5 crore per incident a 15.9% year-on-year increase from ₹22 crore in 2025 according to IBM’s Cost of a Data Breach Report 2026. The scale of breaches also grew, with an average of 39,500 records compromised per incident, up from 38,200 in 2025. AI is playing a dual role in cybersecurity, fueling both attacks and defenses. The report found that 26% of malicious breaches in India were AI-generated, enabling faster, more sophisticated, and scalable cyber threats. Meanwhile, organizations leveraging AI-driven security tools saw significantly lower breach costs and faster response times. Those with extensive AI and automation deployment incurred an average breach cost of ₹21.3 crore, compared to ₹31.6 crore for organizations without such tools. Response times also improved, with AI-equipped firms identifying breaches in 175 days versus 236 days for those without automation. Adoption of AI in cybersecurity remains uneven, however. Only 32% of surveyed organizations reported extensive use of AI and security automation, while 32% used none at all. Unauthorized employee use of AI tools termed "shadow AI" emerged as a key cost driver, increasing breach expenses by ₹1.79 crore. Other major factors included regulatory non-compliance and cloud migration challenges. Industry-wise, financial services bore the highest average breach cost at ₹40.9 crore, followed by technology (₹35.7 crore) and communications (₹34.5 crore). Phishing, including voice and SMS-based attacks, remained the leading initial attack vector (19%), ahead of drive-by compromises (16%) and supply chain breaches (15%). Proactive security measures proved effective in mitigating costs. Offensive security testing, such as red teaming and penetration testing, reduced breach expenses by ₹2.47 crore on average, while threat hunting and AI governance also delivered significant savings. The findings underscore the growing divide between organizations that embrace AI-driven defenses and those that lag behind, as cyber threats continue to evolve.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: ₹25.5 crore per incidentData Compromised: 39,500 records per incident
DATA BREACH
Number Of Records Exposed: 39,500
Cyber Attack
01 Jan 2026IBM
IBM: How AI-enabled attacks cost companies millions

AI-Driven Cyberattacks Surge, Driving Up Breach Costs in 2026

566After Incident
CRITICAL-58
IBM1785868475
IBM Study: AI-Driven Cyberattacks Surge, Driving Up Breach Costs in 2026 A new report from IBM reveals that AI is transforming the cyber threat landscape, enabling attackers to launch faster, cheaper, and more sophisticated breaches while organizations face rising financial and operational costs. In 2026, one in four data breaches was AI-enabled, marking a 56% increase from the previous year. These attacks cost an average of $6 million, nearly $1 million more than the global breach average. The energy and financial services sectors were the hardest hit, accounting for 62% of all AI-driven breaches. Financial services alone saw average breach costs reach $6.29 million. Ransomware incidents also climbed, rising from 34% to 39% of reported attacks, as threat actors leverage AI to generate malware, deepfakes, and phishing campaigns. Nearly half (45%) of AI-enabled attacks involved deepfake impersonation, while 19% used AI-generated malware and 17% relied on AI-crafted phishing. IBM’s findings highlight a growing gap between attack speed and organizational response. Companies that detected and contained breaches quickly saw lower costs, yet many struggle to match the pace of AI-driven threats. While over half of organizations use AI for threat detection, only 18% apply it to vulnerability management. Additionally, 20% of breaches targeted AI models or applications, with compromised APIs, cloud misconfigurations, and insecure plug-ins among the top vulnerabilities. Despite the risks, AI and automation in security operations reduced breach costs by nearly $2 million on average. However, one in four organizations has yet to adopt these tools. In response, 85% of companies plan to increase security spending to counter AI-related threats, with 75% prioritizing the deployment of AI-driven agents for alert triage, vulnerability management, and penetration testing.
INCIDENT DETAILS -
TYPE
AI-enabled breachRansomware
IMPACT
Financial Loss: $6 million (average per breach)
DECEMBER 2025
622Before Incident
Vulnerability
26 Dec 2025IBM
IBM: Critical IBM API Connect Vulnerability Enables Authentication Bypass

IBM API Connect Authentication Bypass Vulnerability (CVE-2025-13915)

620After Incident
CRITICAL-2
IBM1767621759
IBM Patches Critical Authentication Bypass Flaw in API Connect (CVE-2025-13915) IBM has released security updates to address a critical authentication bypass vulnerability in its API Connect platform, tracked as CVE-2025-13915, which carries a CVSS score of 9.8. The flaw allows remote attackers to circumvent authentication controls, granting unauthorized access to affected applications without requiring user interaction or prior privileges. The vulnerability, classified under CWE-305 (Authentication Bypass by Primary Weakness), stems from a failure in enforcing authentication checks under specific conditions. Exploitation could lead to a full compromise of confidentiality, integrity, and availability within the affected IBM API Connect environment, exposing sensitive data and backend services. ### Affected Versions The flaw impacts the following IBM API Connect releases: - V10.0.8.0 through V10.0.8.5 - V10.0.11.0 IBM has released interim fixes (iFixes) for all affected versions and urges immediate patching. For organizations unable to apply updates immediately, a temporary mitigation involves disabling self-service sign-up on the Developer Portal, though this does not fully resolve the risk. ### Impact and Response Given the severity of the flaw, security teams are advised to prioritize remediation and review API access logs for signs of unauthorized activity. The vulnerability was published in the National Vulnerability Database (NVD) on December 26, 2025, with IBM listed as the source. IBM API Connect is widely used in enterprise environments for API management, developer access control, and secure integrations, making this flaw particularly high-risk for connected systems. Organizations running affected versions should assess their deployments and apply fixes without delay.
INCIDENT DETAILS -
TYPE
Authentication Bypass
IMPACT
Data Compromised: Sensitive data and backend services managed through the platformSystems Affected: IBM API Connect applicationsOperational Impact: Complete compromise of confidentiality, integrity, and availability within the affected environment
DATA BREACH
Sensitivity Of Data: Sensitive data
NOVEMBER 2025
646Before Incident
Breach
12 Nov 2025IBM
IBM: Cost of Data Breach

AI-Driven Data Breaches Highlighted in IBM Report

616After Incident
CRITICAL-30
IBM1769139287
IBM Report Highlights AI-Driven Data Breaches as a Growing Threat to Organizations IBM’s latest Cost of a Data Breach Report reveals a critical vulnerability in the rush to adopt AI: a widening gap between AI governance and security oversight is leaving sensitive data exposed. The study, which analyzed 600 breached organizations across 17 industries worldwide, underscores the financial and operational risks of inadequate data protection in AI initiatives. Key findings include: - Operational disruption impacted 31% of breached organizations, with recovery costs and downtime straining resources. - AI supply chain and model attacks contributed to 60% of breaches, directly compromising data integrity. - Beyond immediate financial losses including regulatory fines breaches eroded customer trust, leading to reputational damage and churn. For chief data officers (CDOs) and data leaders, the report serves as a stark reminder of the dual challenge they face: accelerating AI-driven innovation while safeguarding data against evolving threats. The findings position data security not just as a technical issue but as a strategic leadership priority, demanding stronger governance frameworks to balance transformation with resilience.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: Regulatory finesOperational Impact: Operational disruption (31% of breached organizations)Brand Reputation Impact: Eroded customer trust, reputational damage, and churn
DATA BREACH
Type Of Data Compromised: Sensitive dataSensitivity Of Data: High
NOVEMBER 2025
647Before Incident
Vulnerability
06 Nov 2025IBM
IBM

645After Incident
LOW-2
IBM4593045110625
The incident involves a 403 Forbidden error, indicating unauthorized or restricted access to an IBM web resource. While the error itself does not explicitly detail a cybersecurity breach, such errors can sometimes mask underlying security issues like misconfigured access controls, failed authentication attempts, or potential probing by malicious actors. If this error persists across critical systems or is part of a larger pattern (e.g., repeated unauthorized access attempts), it could signal a vulnerability in IBM’s web infrastructure—either an exposed endpoint, improper permission settings, or a precursor to a more severe attack (e.g., reconnaissance for a future breach). Without additional context, the direct impact remains unclear, but unauthorized access attempts or misconfigurations could lead to data exposure or system compromise if left unaddressed.
INCIDENT DETAILS -
TYPE
Access Denial / Unauthorized Access Attempt (403 Forbidden Error)
IMPACT
Potential IBM web page or service (unconfirmed)Operational Impact: Possible minor disruption for users attempting to access the specific IBM page.Brand Reputation Impact: Minimal (if any), as this appears to be an isolated access error rather than a breach.
OCTOBER 2025
648Before Incident
Vulnerability
25 Oct 2025IBM
IBM

646After Incident
LOW-2
IBM4862048102525
The incident involves a 403 Forbidden error, which typically indicates unauthorized access to a restricted resource on IBM’s systems. While the error message itself does not disclose specifics, such incidents can stem from misconfigured access controls, failed authentication attempts, or potential probing by malicious actors (e.g., cyber attackers testing for vulnerabilities). If this error resulted from an external attack—such as a brute-force attempt, credential stuffing, or exploitation of an exposed API—it could signal a security weakness in IBM’s web infrastructure. However, the provided details do not confirm data compromise, system breach, or operational disruption. The lack of further context (e.g., logs, incident reports) limits assessment to a potential low-impact security event, though it warrants investigation to rule out targeted reconnaissance or early-stage cyber threats.
INCIDENT DETAILS -
TYPE
access_denialpotential_security_control_trigger
IMPACT
unspecified_IBM_web_pageDowntime: temporary (until access is restored or permissions corrected)Operational Impact: minor (limited to inability to access a specific page)Brand Reputation Impact: low (unless part of a broader outage or misconfiguration trend)
SEPTEMBER 2025
672Before Incident
Breach
03 Sep 2025IBM
IBM (as referenced in the study with Palo Alto Networks)

Security Architecture Bloat and Fragmentation Leading to Increased Cybersecurity Risks

642After Incident
HIGH-30
IBM500090325
The article highlights systemic vulnerabilities in IBM’s research, where organizations managing an average of 83 security tools from 29 vendors face severe operational inefficiencies. Fragmented architectures—exemplified by IBM’s findings—create blind spots, with 95% of security leaders admitting redundant tools lack full integration. This sprawl leads to 72-day delays in threat detection and 84-day delays in containment, directly enabling attackers to exploit gaps. The study underscores that one-third of breaches originate from phishing, with Secure Email Gateways (SEGs) failing to block an average of 67.5 phishing emails per 100 mailboxes monthly. Default configurations, misaligned protections, and unintegrated tools amplify risks, resulting in missed handoffs, poor detection, and inflated response costs. The cumulative effect is reputational damage, financial loss from prolonged breaches, and erosion of customer trust, particularly for smaller teams lacking resources to maintain defenses. IBM’s own data reveals that non-consolidated environments suffer 101% lower ROI compared to unified platforms, signaling systemic exposure to sophisticated social engineering and evolving threat tactics that bypass static defenses.
INCIDENT DETAILS -
TYPE
Operational RiskTool SprawlPhishing VulnerabilitySecurity Architecture Fragmentation
IMPACT
Email Systems (SEGs)Endpoint SecurityIdentity Management72-day longer threat detection84-day longer threat containmentIncreased operational risk due to tool sprawlStretched security teamsHigher response costsReputational damage due to delayed breach detection/responsePerceived insecurity by customers/partnersCredential theft via phishing
DATA BREACH
Credentials (via phishing)Potential PII (if phishing successful)High (credentials)Medium (corporate email access)Potential (if phishing leads to account takeover)
JUNE 2025
664Before Incident
Vulnerability
05 Jun 2025IBM
IBM

IBM Cloud Outage and Critical Vulnerability

661After Incident
CRITICAL-3
IBM347060525
IBM experienced a cloud outage on Wednesday that lasted over four hours, causing users to be unable to access the console for managing their cloud resources or to open and view support cases. This outage repeated a similar incident from Tuesday. Additionally, IBM identified a critical-rated vulnerability in its QRadar threat detection and response tools and Cloud Pak for Security integration suite, which left a password in a configuration file. The vulnerability was scored 9.6 on the Common Vulnerability Scoring System, and IBM's security bulletin also advised of four other QRadar flaws.
INCIDENT DETAILS -
TYPE
Outage and Vulnerability
IMPACT
IBM Cloud ConsoleSupport Cases2023-05-21 09:03 AM UTC2023-05-21 01:20 PM UTCOperational Impact: Users unable to access cloud resources and support casesBrand Reputation Impact: Apologies issued by IBM Japan
MAY 2025
662Before Incident
Vulnerability
01 May 2025IBM
IBM

660After Incident
LOW-2
IBM3762037111125
The incident involves a 403 Forbidden error on an IBM web page, indicating unauthorized access or a misconfigured security restriction. While the error itself does not explicitly detail a cyberattack, it may suggest a potential access control vulnerability or an unintended exposure of internal systems. If exploited, such vulnerabilities could allow attackers to probe deeper into IBM’s infrastructure, potentially leading to data exposure or service disruptions. The incident reference number (18.561e1202.1762842001.646fd49b) implies internal tracking, but no public details confirm data breaches or operational impact. However, unaddressed access flaws could escalate into broader security risks, including credential stuffing, API abuses, or reconnaissance for targeted attacks. IBM’s global scale means even minor vulnerabilities could have cascading effects if left unresolved.
INCIDENT DETAILS -
TYPE
access_denialpotential_security_control_trigger
IMPACT
IBM webpage (unspecified)Downtime: temporary (until access is restored or issue is resolved)Operational Impact: minor (limited to inability to access a specific page)Brand Reputation Impact: low (unless recurrent or part of a larger pattern)
MARCH 2025
709Before Incident
Breach
01 Mar 2025IBM
Ponemon Institute and IBM: India Records Its Highest Average Cost of a Data Breach at INR 255 Million (INR 25.5 Crore) in 2026: IBM Report

India’s Data Breach Costs Hit Record High as AI Reshapes Cyber Threats

658After Incident
CRITICAL-51
PONIBM1785738483
India’s Data Breach Costs Hit Record High as AI Reshapes Cyber Threats India’s cybersecurity landscape faced escalating challenges in 2026, with the average cost of a data breach surging to INR 255 million (₹25.5 crore), a 15.9% increase from 2025, according to IBM’s 2026 Cost of a Data Breach Report. The study, conducted by the Ponemon Institute and analyzed by IBM, examined breaches at 602 global organizations between March 2025 and February 2026, with a follow-up survey of 456 respondents in May 2026. ### Key Findings: AI’s Dual Role in Cybersecurity The report revealed a growing divide in AI adoption among Indian organizations. While 26% of malicious breaches involved AI-generated attacks accelerating threat sophistication only 32% of organizations extensively used AI and security automation. Another 36% had limited deployment, and 32% used none at all. This gap had financial and operational consequences: - Cost disparity: Breaches at organizations with no AI/automation cost INR 316 million (₹31.6 crore), compared to INR 213 million (₹21.3 crore) for those with extensive use. - Slower response times: Non-automated organizations took 236 days to detect and 75 days to contain breaches, versus 175 days and 81 days, respectively, for automated counterparts. - Shadow AI risks: Unauthorized AI use added INR 17.9 million (₹1.79 crore) to breach costs, ranking among the top three cost amplifiers alongside regulatory non-compliance and cloud migration. ### Sector-Specific and Attack Trends - Highest-cost sectors: Financial services (INR 409 million/₹40.9 crore), technology (INR 357 million/₹35.7 crore), and communications (INR 345 million/₹34.5 crore) bore the brunt of breaches. - Top attack vectors: Phishing (19%), drive-by compromise (16%), and supply chain attacks (15%) dominated. - Cost-saving measures: Offensive security testing (e.g., red teaming) reduced costs by INR 24.7 million (₹2.47 crore), followed by proactive threat hunting and AI governance tools. ### Post-Breach Investments Organizations prioritized strengthening defenses, with 67% planning to enhance incident response plans, 51% investing in threat detection technologies (SIEM/SOAR/EDR), and 39% focusing on AI security and governance tools. Gaurav Agarwal, VP of Technology at IBM India & South Asia, emphasized the need for end-to-end AI integration across security operations, noting that current deployments often focus solely on detection. The report underscored that while AI-driven threats are rising, strategic automation and governance can mitigate costs and improve resilience.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: INR 255 million (₹25.5 crore) average cost per breach
Cyber Attack
01 Mar 2025IBM
IBM and Ponemon Institute: IBM: AI-Enabled Breaches Cost $6M on Average

AI-Enabled Breaches Surge, Costing Organizations $6 Million on Average in 2026

658After Incident
CRITICAL-51
IBMPON1785321521
AI-Enabled Breaches Surge, Costing Organizations $6 Million on Average in 2026 A new IBM study reveals that one in four malicious data breaches in 2026 were AI-enabled, marking a 56% increase from the previous year. These attacks primarily involving deepfake impersonation and AI-driven malware are accelerating breach economics, making attacks faster and cheaper to execute while driving up recovery costs. The average AI-related breach now costs $6 million, nearly $1 million more than the global average of $4.99 million. The 2026 Cost of a Data Breach Report, conducted by the Ponemon Institute and analyzed by IBM, surveyed 602 organizations worldwide between March 2025 and February 2026. A follow-up study in May 2026 found that 85% of organizations plan to increase security spending in response to advanced AI threats, compared to 64% that would do so after experiencing a breach. Despite this shift, only 18% of organizations use AI-driven agents for vulnerability management, leaving critical gaps in defense as exploit windows shrink. Critical infrastructure sectors particularly financial services and energy were the most targeted, with 62% of AI-driven attacks directed at these industries. Breaches in financial services averaged $6.3 million, while energy sector incidents cost $5.2 million, raising concerns about systemic economic and supply chain disruptions. The report also highlights key vulnerabilities in AI systems, with 20% of organizations reporting breaches targeting AI models or applications. The most common attack vectors were compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations (27%). Additionally, encryption gaps persist, with only 37% of breached organizations encrypting sensitive data both at rest and in transit, and just 34% maintaining visibility into cryptographic assets. Ransomware attacks also rose, accounting for 39% of incidents (up from 34% the prior year), with threat actors increasingly leveraging AI to automate attacks and exploit brand reputation (41%), employee data (35%), and intellectual property (31%). IBM Security VP Suja Viswesan noted that the growing imbalance between attack costs and breach expenses is reshaping cyber risk, emphasizing the need for faster remediation, runtime identity security, and integrated vulnerability management to match attackers’ speed. The findings underscore the urgency for organizations to adopt AI-driven security tools, as those using automation in security operations reduced breach costs by nearly $2 million yet 25% of organizations still lack these capabilities.
INCIDENT DETAILS -
TYPE
AI-enabled breachdata breachransomware
MOTIVATION
financial gainbrand reputation exploitationintellectual property theft
IMPACT
Financial Loss: $6 million (average for AI-related breaches)AI modelsapplicationscloud systemssystemic economic disruptionssupply chain disruptions
DATA BREACH
employee dataintellectual propertybrand reputation dataSensitivity Of Data: high37% encrypted at rest and in transit
JANUARY 2025
709Before Incident
Vulnerability
30 Jan 2025IBM
IBM

707After Incident
LOW-2
IBM4262042091025
The incident involves a 403 Forbidden error, indicating unauthorized access to an IBM web resource (Incident ID: 18.ceb0f748.1757485191.4eafbe3). While the error itself does not confirm a breach, it suggests a potential misconfigured access control, exposed internal page, or failed security measure that could allow attackers to probe for vulnerabilities. If exploited, this could lead to unauthorized data exposure, credential harvesting, or further system infiltration. The lack of public details implies IBM may have mitigated the issue internally, but the incident highlights risks of improper access restrictions, which are common entry points for cyber attacks. Without evidence of data theft or operational disruption, the impact remains speculative but warrants classification as a security vulnerability requiring remediation to prevent escalation.
INCIDENT DETAILS -
TYPE
access_denialpotential_security_control_trigger
IMPACT
unspecified_IBM_web_pageDowntime: temporary (until access is restored or issue is resolved)Operational Impact: minor (limited to inability to access a specific page)Brand Reputation Impact: low (unless part of a larger outage or targeted attack)
JUNE 2024
762Before Incident
Breach
16 Jun 2024IBM
IBM (as referenced in the article)

689After Incident
CRITICAL-73
IBM5434154110425
The article highlights IBM’s 2024 Cost of a Data Breach Report, which underscores escalating financial and operational damages from breaches due to prolonged investigations, regulatory scrutiny, and unauthorized data exposure—including leaks via ungoverned AI tools or improper file sharing. The report aligns with broader trends cited by ENISA (2024), noting persistent ransomware and data theft targeting sensitive corporate and customer data. These breaches exploit weak access controls, unclear permissions, and inadequate audit trails in virtual data rooms (VDRs), leading to costly remediation, reputational harm, and compliance violations. The financial impact is compounded by delayed incident response, where breaches involving high-value data (e.g., M&A documents, employee records, or customer PII) incur higher cleanup costs and regulatory penalties. The article implies that organizations using substandard VDRs face increased risk of insider threats, third-party leaks, or ransomware attacks, as demonstrated by real-world cases where unauthorized AI processing or mass downloads of sensitive files went undetected until post-breach forensics. The cumulative effect threatens deal integrity, investor trust, and long-term business viability, particularly in high-stakes sectors like finance, healthcare, or critical infrastructure.
INCIDENT DETAILS -
TYPE
Data Breach RiskCybersecurity Advisory
IMPACT
Financial Loss: Potential high costs due to prolonged breach investigations, regulatory fines, and cleanup (cited from IBM’s 2024 *Cost of a Data Breach*).Virtual Data Rooms (VDRs)Sensitive Deal DocumentsAI Processing ToolsOperational Impact: Slowed dealmaking processes due to heightened scrutiny, manual reviews, and distrust in insecure VDRs.Brand Reputation Impact: Risk of reputational damage if breaches occur due to inadequate VDR security, leading to loss of trust in dealmaking partners.Legal Liabilities: Potential violations of data protection regulations (e.g., GDPR) due to uncontrolled data transfers or leaks.
DATA BREACH
Sensitive Deal DocumentsPII (Potential)Financial RecordsLegal ContractsSensitivity Of Data: High (M&A, financings, audits, board matters)Data Exfiltration: Risk highlighted due to loose permissions and unapproved AI tool usage.PDFOffice DocumentsMedia FilesPersonally Identifiable Information: Potential (if PII is stored in VDRs without proper controls).
Breach
16 Jun 2024IBM
IBM: Average Cost of a Healthcare Data Breach Falls to $7.42 Million

Healthcare Data Breach Costs Drop, but U.S. Breaches Hit Record High in 2025

689After Incident
CRITICAL-73
IBM1769139399
Healthcare Data Breach Costs Drop, but U.S. Breaches Hit Record High in 2025 IBM’s 2025 Cost of a Data Breach Report reveals a mixed landscape for cybersecurity costs, with global averages declining for the first time in five years while U.S. breaches reach unprecedented levels. The study, based on data from 600 organizations across 16 countries and 17 industries, found that the global average cost of a data breach fell to $4.44 million, down from previous years. However, U.S. breaches surged to a record $10.22 million, a 9.2% increase from 2024, driven by higher regulatory fines and escalation costs. Healthcare remained the most expensive industry for breaches, though costs dropped significantly $7.42 million on average, down $2.35 million year-over-year. Despite the decline, healthcare breaches still took the longest to detect and contain (279 days), five weeks longer than the global average of 241 days, a nine-year low. Key Trends and Findings: - Initial Access Vectors: Phishing (16%) overtook stolen credentials (10%) as the top attack method, with supply chain compromise (15%) ranking second. - Ransomware: While attacks persist, fewer organizations paid ransoms 63% refused in 2025, up from 59% in 2024. Ransom demands averaged $5.08 million, but law enforcement involvement (now at 40%, down from 52%) reduced breach costs by $1 million when utilized. - Operational Impact: Nearly all breached organizations faced disruptions, with most taking over 100 days to recover. Nearly half (49%) planned to offset costs by raising prices, with a third considering increases of 15% or more. - Cost Drivers: Detection and escalation ($1.47 million), lost business ($1.38 million), and post-breach response ($1.2 million) remained the largest expense categories, though all saw slight declines. - Mitigation Factors: DevSecOps (-$227K), AI/ML-driven insights (-$223K), and security analytics (-$212K) were the most effective at reducing costs. Conversely, supply chain breaches (+$227K), security complexity (+$207K), and shadow IT (+$200K) unauthorized software or devices drove costs higher. Organizations with high shadow IT levels faced $670K more in breach expenses. - AI Risks: AI adoption outpaced governance, with 97% of breached organizations lacking proper AI access controls. 13% of organizations reported AI-related security incidents, while 16% of breaches involved attacker-used AI, primarily for phishing (37%) and deepfakes (35%). - Investment Shifts: Only 49% of organizations plan to increase cybersecurity spending in the next year, down from 66% in 2024, with less than half prioritizing AI-driven solutions. The report underscores persistent vulnerabilities in healthcare, the financial toll of delayed breach responses, and the growing risks of ungoverned AI and shadow IT in enterprise environments.
INCIDENT DETAILS -
TYPE
Data BreachRansomware
IMPACT
Financial Loss: $4.44 million (global average), $10.22 million (U.S. average), $7.42 million (healthcare average)Downtime: >100 days for recoveryOperational Impact: Nearly all breached organizations faced disruptions
JANUARY 2024
794Before Incident
Breach
01 Jan 2024IBM
IBM and Federal Trade Commission: Digital Defense: The true cost of a data breach

Data Breach Impacts Extend Far Beyond IT From Personal Fraud to Business Disruptions

753After Incident
CRITICAL-41
FEDIBM1782872861
Data Breach Impacts Extend Far Beyond IT From Personal Fraud to Business Disruptions A data breach carries severe consequences for individuals, businesses, and defense contractors, with financial, operational, and reputational damage that can persist long after the initial incident. For individuals, exposed data such as passwords or Social Security numbers can lead to identity theft, account takeovers, and financial fraud. In 2024, the Federal Trade Commission reported over 1.1 million identity theft cases and $12.5 billion in fraud losses. Beyond monetary harm, victims often face months of recovery, including disputing charges, freezing credit, and correcting records, with lingering stress even after resolution. Businesses face even steeper costs. IBM’s 2024 Cost of a Data Breach report found the global average breach cost reached $4.88 million, encompassing downtime, lost productivity, legal fees, compliance work, and reputational harm. Notably, 70% of breached organizations experienced significant disruption, with stolen or compromised credentials identified as the most common attack vector. For defense contractors, breaches pose additional risks to compliance and contract eligibility. The Cybersecurity Maturity Model Certification (CMMC) framework enforces safeguards for handling Federal Contract Information and Controlled Unclassified Information. CMMC Level 1 mandates 15 basic requirements, while Level 2 aligns with 110 NIST SP 800-171 controls, and Level 3 introduces advanced protections for high-risk environments. Stronger cybersecurity measures not only reduce breach risks but also help maintain operational integrity and contract readiness. Ultimately, the fallout from a breach financial loss, operational disruption, and eroded trust underscores the need for proactive security across all sectors.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $4.88 million (global average)PasswordsSocial Security numbersPersonally Identifiable InformationOperational Impact: Significant disruption (70% of breached organizations)Brand Reputation Impact: Eroded trustLegal Liabilities: Legal fees, compliance workIdentity Theft Risk: Over 1.1 million identity theft cases in 2024
DATA BREACH
PasswordsSocial Security numbersPersonally Identifiable InformationSensitivity Of Data: HighPersonally Identifiable Information: Yes
SEPTEMBER 2023
821Before Incident
Breach
22 Sep 2023IBM
International Business Machines Corporation

Unauthorized Access to Personal Information on IBM's Janssen CarePath Platform

791After Incident
CRITICAL-30
IBM040091825
The California Office of the Attorney General disclosed that IBM suffered an unauthorized access incident affecting the Janssen CarePath platform, a database containing personal information. The breach was reported on September 22, 2023, though the exact date of the intrusion remains undisclosed. While the specifics of the compromised data were not detailed in the report, the incident involved the exposure of personal information, likely belonging to customers or patients associated with the platform. Given the nature of Janssen CarePath—a service supporting healthcare-related financial and treatment assistance—the breach raises concerns about potential misuse of sensitive health or personally identifiable information (PII). IBM has not publicly confirmed the scale of the breach or whether the exposed data was exfiltrated, but the involvement of a government authority suggests regulatory scrutiny and possible compliance implications under data protection laws like CCPA (California Consumer Privacy Act) or HIPAA (Health Insurance Portability and Accountability Act) if health data was impacted.
INCIDENT DETAILS -
TYPE
Data Breach / Unauthorized Access
IMPACT
Personal InformationJanssen CarePath platform databaseIdentity Theft Risk: Potential (personal information exposed)
DATA BREACH
Personal InformationSensitivity Of Data: High (personal information)
MAY 2020
810Before Incident
Cyber Attack
01 May 2020IBM
IBM (Healthcare Sector Example)

800After Incident
CRITICAL-10
IBM1362513090425
The IBM report highlights the escalating financial toll of data breaches in the healthcare industry, which consistently ranks as the most expensive sector for such incidents. Between May 2020 and February 2025, the average cost of a healthcare data breach surged to $10.93 million USD, the highest across all industries. These breaches often involve the exposure of highly sensitive patient records, including medical histories, treatment details, and personally identifiable information (PII). A typical incident in this sector may stem from a cyber attack—such as ransomware or targeted hacking—where threat actors exploit vulnerabilities in hospital IT systems or third-party vendors.The consequences extend beyond financial losses, disrupting critical healthcare services. For instance, a ransomware attack could encrypt patient databases, delaying emergency treatments, surgeries, or diagnostic procedures. In extreme cases, such disruptions have been linked to increased patient mortality rates. The breach’s ripple effects also erode public trust, trigger regulatory fines (e.g., HIPAA violations), and necessitate costly remediation efforts, including system overhauls and credit monitoring for affected individuals.Given the life-or-death stakes of healthcare data integrity, these breaches are classified among the most severe, often involving criminal hackers or state-sponsored groups targeting intellectual property (e.g., drug patents) or aiming to destabilize regional health infrastructure.
INCIDENT DETAILS -
TYPE
Data Breach Cost Analysis
IMPACT
Description: Average cost per breach varies by industry (e.g., Healthcare: ~$10.93M in 2025, Financial: ~$5.9M in 2025). Refer to the source graph for industry-specific values.Trend: Increasing annually across all industries from 2020 to 2025.
APRIL 2020
811Before Incident
Vulnerability
01 Apr 2020IBM
IBM

IBM Data Risk Manager Zero-Day Vulnerabilities

809After Incident
HIGH-2
IBM162291222
Four zero-day vulnerabilities impacted an IBM security product after the company refused to patch bugs following a private bug disclosure attempt. The bugs impacted the IBM Data Risk Manager (IDRM). It is an enterprise security tool that aggregates feeds from vulnerability scanning tools and other risk management tools to let admins investigate security issues. The compromise of product led to a full-scale company compromise, as the tool had credentials to access other security tools. It contained information about critical vulnerabilities that affect the company.
INCIDENT DETAILS -
TYPE
Zero-Day Exploit
IMPACT
Critical vulnerability informationIBM Data Risk ManagerOther security toolsOperational Impact: Full-scale company compromise
NOVEMBER 2017
824Before Incident
Breach
08 Nov 2017IBM
IBM: Washington Nationals say ‘Ooooooooooooo Canada’ ahead of Friendship Day game with Blue Jays. And, there’s a special, exclusive hat.

Canadian Data Breach Costs and Detection Times Hit Record Highs

794After Incident
MEDIUM-30
IBM1785328112
IBM Report: Canadian Data Breach Costs and Detection Times Hit Record Highs A recent IBM report reveals that the average cost of a data breach in Canada has risen, alongside longer detection and containment times. The findings highlight growing financial and operational risks for organizations as cyber threats become more sophisticated. The report, part of IBM’s annual Cost of a Data Breach study, indicates that Canadian businesses now face higher expenses per incident, driven by factors such as regulatory fines, remediation efforts, and reputational damage. Additionally, the time required to identify and mitigate breaches has increased, leaving systems exposed for longer periods. While the report does not specify exact figures for Canada, global trends suggest that industries like healthcare, finance, and critical infrastructure remain prime targets. The rise in remote work and digital transformation has further expanded attack surfaces, complicating cybersecurity defenses. The findings underscore the escalating challenges for Canadian organizations in managing cyber risks amid evolving threats.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: Higher expenses per incidentOperational Impact: Longer detection and containment timesBrand Reputation Impact: Reputational damageLegal Liabilities: Regulatory fines
JANUARY 2013
833Before Incident
Breach
01 Jan 2013IBM
IBM and AT&T: Whistleblower Accuses IBM, AT&T of Covering Up Breaches

IBM and AT&T Accused of Covering Up Years-Long Data Breaches by Chinese Hackers

799After Incident
CRITICAL-34
ATTIBM1780946436
IBM and AT&T Accused of Covering Up Years-Long Data Breaches by Chinese Hackers A recently unsealed whistleblower lawsuit alleges that IBM and AT&T concealed multiple data breaches spanning from 2013 to 2016, including attacks attributed to Chinese state-backed hackers. William Barlow, IBM’s former vice president of threat intelligence, claims the company knew of breaches affecting its core network but failed to disclose them to authorities. The complaint asserts that Chinese threat actor APT 10 may have breached IBM’s systems over 56,000 times during the three-year period. Despite an alert from the Five Eyes intelligence alliance in 2017 prompting an internal investigation, IBM allegedly lacked critical logs to determine the scope of the breaches a lapse in standard security practices. The lawsuit further states that neither IBM nor AT&T could confirm what data was accessed, altered, or exfiltrated due to poor network design and insufficient logging. Barlow also alleges that breaches extended to at least two IBM subsidiaries, which were similarly concealed. AT&T, which managed IBM’s network infrastructure, is named in the complaint for its role in the alleged cover-up. IBM has denied wrongdoing, stating that the complaint filed six years ago was reviewed by the U.S. Department of Justice, which declined to intervene. A company spokesperson maintained that IBM’s actions complied with legal requirements. The case highlights long-standing concerns over corporate transparency in cybersecurity incidents involving state-sponsored threat actors.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
State-sponsored espionage
IMPACT
Systems Affected: IBM’s core network, at least two IBM subsidiaries
Cyber Attack
01 Jan 2013IBM
IBM and Truven: Former cyber executive turned whistleblower accuses IBM of covering up several data breaches

Alleged Decade-Long Cover-Up of State-Sponsored Cyberattacks on IBM

799After Incident
CRITICAL-34
MERIBM1780698286
Former IBM Executive Alleges Decade-Long Cover-Up of State-Sponsored Cyberattacks A recently unsealed 2020 lawsuit filed by William Barlow, IBM’s former vice president of threat intelligence, accuses the company of concealing multiple cyber breaches including attacks by foreign governments over the past decade. Barlow, who left IBM in August 2019, claims the tech giant failed to disclose breaches of its core network and subsidiaries, despite evidence of extensive compromise. The lawsuit centers on a 2013–2016 campaign attributed to APT 10, a Chinese state-linked hacking group indicted by the U.S. in 2018. According to Barlow, intelligence officials from the Five Eyes alliance (U.S., U.K., Canada, Australia, and New Zealand) warned IBM of the breach in March 2017, prompting an internal investigation. The probe found that APT 10 potentially breached IBM’s network over 56,000 times, compromising 400 accounts and nearly 200 systems across 18 countries and multiple business units. However, IBM allegedly did not retain access logs, hindering further investigation. Barlow further alleges that IBM never notified government authorities or customers, including the U.S. federal government a major IBM client. The complaint describes IBM’s infrastructure as outdated and vulnerable, with hackers moving undetected across its systems. Additionally, Barlow claims breaches at two IBM subsidiaries: Trusteer (a cybersecurity firm acquired in 2013) in 2018 and Truven (a healthcare data company acquired in 2016), which was allegedly breached multiple times post-acquisition. IBM has denied wrongdoing, stating the lawsuit is six years old and that the U.S. Department of Justice declined to intervene. The company maintains it acted within the law. Barlow’s lawyer has indicated plans to aggressively litigate the case, framing the allegations as incompatible with IBM’s role as a federal cybersecurity vendor. The case highlights concerns over undisclosed breaches at major tech firms, even as stricter data breach notification laws have been enacted in recent years.
INCIDENT DETAILS -
TYPE
State-sponsored cyberattackData breach
MOTIVATION
EspionageData exfiltration
IMPACT
Data Compromised: YesSystems Affected: Nearly 200 systemsOperational Impact: Extensive compromise across multiple business unitsBrand Reputation Impact: Potential damage due to undisclosed breachesLegal Liabilities: Potential regulatory and legal actions
DATA BREACH
Sensitivity Of Data: Potentially high (healthcare data, federal client data)Data Exfiltration: SuspectedPersonally Identifiable Information: Potentially (healthcare data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for IBM ?
?
What was IBM's A.I Rankiteo Cyber Score in July 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in June 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in May 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in April 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in March 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in February 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in January 2026 ?
?
What was IBM's A.I Rankiteo Cyber Score in December 2025 ?
?
What was IBM's A.I Rankiteo Cyber Score in November 2025 ?
?
What was IBM's A.I Rankiteo Cyber Score in October 2025 ?
?
What was IBM's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on IBM's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with IBM ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view IBM's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?