What happened
In March 2011 attackers stole information related to RSA's SecurID two-factor authentication product after two small groups of RSA employees were sent spear phishing emails carrying a booby-trapped Excel attachment. RSA executive Uri Rivner publicly described the lure email as being titled '2011 Recruitment Plan.' The stolen SecurID data was subsequently used in attempted intrusions at US defense contractors, and RSA offered to replace tokens for customers.
How the deception worked
Two batches of emails, each to a small group of non-executive employees, carried an Excel spreadsheet named for a '2011 Recruitment Plan.' At least one recipient retrieved the message from their junk folder and opened it. The workbook embedded an Adobe Flash object exploiting a then-unpatched zero-day (CVE-2011-0609), which dropped a Poison Ivy remote access tool configured in reverse-connect mode. The attackers then harvested credentials, escalated to administrative and service accounts, staged data in password-protected RAR archives and exfiltrated it over FTP to an external staging host, taking SecurID-related information with them.
AI involvement · No AI reported
Pre-dates generative AI tooling; no AI component reported.
The control that would have caught it· our reading, not a claim from the sources
Attachment sandboxing and aggressive third-party plugin patching would have blunted the exploit, and segmenting the seed-record environment from general corporate desktops would have contained a single opened attachment.
Sources (3)
- RSA: SecurID Attack Was Phishing Via an Excel SpreadsheetThreatpost·threatpost.comOpen ↗
- RSA SecureID Attack Began With Excel File Rigged With Flash Zero-DayDark Reading·darkreading.comOpen ↗
- 'Tricked' RSA Employee Opened Door that Led to APT AttackBankInfoSecurity·bankinfosecurity.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.