Skip to content
NetarxImpact Database
Spear Phishing (Email)No AI reportedConfirmed

RSA SecurID breach begins with '2011 Recruitment Plan' spear phishing email

RSA Security (EMC) · Technology · United States · March 2011

Business impact
$66,000,000
Lost revenue, earnings impact, remediation cost, a settlement or damages sought. Not money stolen.
EMC publicly attributed roughly $66 million of incident-related costs (including token replacement and monitoring) to the breach across 2011 quarters; press reporting of that figure is consistent, but the number is a company estimate rather than an audited breach loss.

What happened

In March 2011 attackers stole information related to RSA's SecurID two-factor authentication product after two small groups of RSA employees were sent spear phishing emails carrying a booby-trapped Excel attachment. RSA executive Uri Rivner publicly described the lure email as being titled '2011 Recruitment Plan.' The stolen SecurID data was subsequently used in attempted intrusions at US defense contractors, and RSA offered to replace tokens for customers.

How the deception worked

Two batches of emails, each to a small group of non-executive employees, carried an Excel spreadsheet named for a '2011 Recruitment Plan.' At least one recipient retrieved the message from their junk folder and opened it. The workbook embedded an Adobe Flash object exploiting a then-unpatched zero-day (CVE-2011-0609), which dropped a Poison Ivy remote access tool configured in reverse-connect mode. The attackers then harvested credentials, escalated to administrative and service accounts, staged data in password-protected RAR archives and exfiltrated it over FTP to an external staging host, taking SecurID-related information with them.

AI involvement · No AI reported

Pre-dates generative AI tooling; no AI component reported.

The control that would have caught it· our reading, not a claim from the sources

Attachment sandboxing and aggressive third-party plugin patching would have blunted the exploit, and segmenting the seed-record environment from general corporate desktops would have contained a single opened attachment.

Sources (3)

  1. RSA: SecurID Attack Was Phishing Via an Excel Spreadsheet
    Threatpost·threatpost.comOpen ↗
  2. RSA SecureID Attack Began With Excel File Rigged With Flash Zero-Day
    Dark Reading·darkreading.comOpen ↗
  3. 'Tricked' RSA Employee Opened Door that Led to APT Attack
    BankInfoSecurity·bankinfosecurity.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.