{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2011-rsa-securid-breach-begins-with-2011-recruitment-plan-spear-phishing-emai"},"incident":{"title":"RSA SecurID breach begins with '2011 Recruitment Plan' spear phishing email","date":"2011-03","date_precision":"month","victim_org":"RSA Security (EMC)","sector":"Technology","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"Pre-dates generative AI tooling; no AI component reported.","outcomes":["Data Breach","Espionage","Supply Chain Compromise"],"loss_usd":66000000,"loss_note":"EMC publicly attributed roughly $66 million of incident-related costs (including token replacement and monitoring) to the breach across 2011 quarters; press reporting of that figure is consistent, but the number is a company estimate rather than an audited breach loss.","records_affected":null,"threat_actor":"Suspected nation-state actor (widely reported as China-linked; never formally attributed by RSA)","summary":"In March 2011 attackers stole information related to RSA's SecurID two-factor authentication product after two small groups of RSA employees were sent spear phishing emails carrying a booby-trapped Excel attachment. RSA executive Uri Rivner publicly described the lure email as being titled '2011 Recruitment Plan.' The stolen SecurID data was subsequently used in attempted intrusions at US defense contractors, and RSA offered to replace tokens for customers.","how_it_worked":"Two batches of emails, each to a small group of non-executive employees, carried an Excel spreadsheet named for a '2011 Recruitment Plan.' At least one recipient retrieved the message from their junk folder and opened it. The workbook embedded an Adobe Flash object exploiting a then-unpatched zero-day (CVE-2011-0609), which dropped a Poison Ivy remote access tool configured in reverse-connect mode. The attackers then harvested credentials, escalated to administrative and service accounts, staged data in password-protected RAR archives and exfiltrated it over FTP to an external staging host, taking SecurID-related information with them.","lessons":"Attachment sandboxing and aggressive third-party plugin patching would have blunted the exploit, and segmenting the seed-record environment from general corporate desktops would have contained a single opened attachment.","confidence":"Confirmed","sources":[{"title":"RSA: SecurID Attack Was Phishing Via an Excel Spreadsheet","url":"https://threatpost.com/rsa-securid-attack-was-phishing-excel-spreadsheet-040111/75099/","publisher":"Threatpost"},{"title":"RSA SecureID Attack Began With Excel File Rigged With Flash Zero-Day","url":"https://www.darkreading.com/cyberattacks-data-breaches/rsa-secureid-attack-began-with-excel-file-rigged-with-flash-zero-day","publisher":"Dark Reading"},{"title":"'Tricked' RSA Employee Opened Door that Led to APT Attack","url":"https://www.bankinfosecurity.com/tricked-rsa-worker-opened-backdoor-to-apt-attack-a-3504","publisher":"BankInfoSecurity"}],"entry_type":"incident","slug":"2011-rsa-securid-breach-begins-with-2011-recruitment-plan-spear-phishing-emai","year":2011,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2011-rsa-securid-breach-begins-with-2011-recruitment-plan-spear-phishing-emai"}}