← Deloitte

2017 Deloitte — 350 client emails, admin account compromise

2017 Unknown records affected Share on X

Data compromised

Client emails, usernames, passwords, IP addresses

Technical writeup

Deloitte, one of the Big Four accounting firms, suffered a breach when attackers gained access to the firm's email server through an administrator account that lacked two-factor authentication. The breach exposed confidential emails of 350 clients.

Root cause

Compromised admin account; poor security (no 2FA)

References