EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/deloitte-email-hack-2017
232/430

File EL-0199CriticalResolvedData Breach / Email Account Compromise

Deloitte Email Hack (2017)

Also filed as Deloitte Global Email Breach · Deloitte Cyber Attack

Deloitte, one of the Big Four accounting firms, suffered a sophisticated cyberattack in 2017 that compromised its global email server. Attackers accessed internal emails containing sensitive client information, including communications from major multinational corporations and government agencies.

  • #deloitte
  • #email-hack
  • #data-breach
  • #consulting
  • #professional-services
  • #client-data
  • #2017
Notoriety8/10
Event
25 Sept 2017
Disclosed
25 Sept 2017
Target
Deloitte
Scale
350,000+ client emails and attachments
Status
Resolved

01Summary

In September 2017, Deloitte disclosed that it had been the victim of a sophisticated cyberattack targeting its global email server. The attackers gained access to the Microsoft Azure-based email platform used by Deloitte's global workforce. The compromised data included emails and attachments from approximately 350,000 customers, containing highly sensitive information about client strategies, legal matters, and confidential business negotiations. The breach was discovered in March 2017 but was not publicly disclosed until September. Deloitte stated that only a small number of accounts were compromised but acknowledged that the attackers had 'deep' access to the system. The breach was particularly damaging because of Deloitte's role as an auditor and consultant to the world's largest corporations and governments.

02Background

Deloitte is one of the Big Four accounting firms, providing audit, tax, consulting, and financial advisory services to a vast global client base including many Fortune 500 companies and government agencies. The firm's access to highly sensitive client data made it a prime target for espionage.

03Key revelations

  1. 01A single compromised administrator account gave attackers access to Deloitte's entire global email system.
  2. 02The breach went undetected for approximately 6 months.
  3. 03The compromised data included highly sensitive client and government communications.

04Technical analysis

The attackers gained access using a compromised administrator account on Deloitte's Azure Active Directory. The single compromised credential allowed access to the entire global email system. The breach was discovered after anomalous login activity was detected.

Attack vector
Compromised administrator credentials
Attack method
Email account takeover via credential compromise
Initial access
Compromised credentials
Exfiltration
Email data extraction

Vulnerabilities exploited

  • Weak or compromised administrator credentials

MITRE ATT&CK techniques

  • T1078

05Threat actor

The perpetrator of the Deloitte hack has never been publicly identified. The sophistication of the attack suggested a well-resourced actor, possibly state-sponsored.

Attribution sources

  • Deloitte Confirmation
  • The Guardian
  • Media Reports

06Victims and impact

Additional victims

  • Deloitte Clients (including major corporations and governments)

Countries affected

  • Global

07Data exposed

Data types

  • Internal Emails
  • Client Communications
  • Strategic Documents
  • Legal Correspondence
  • Confidential Business Data

Notable documents

  • Deloitte internal emails (accessed by attackers)

08Financial damage

Reputational damage, client trust erosion, potential legal liability.

09Timeline

  1. 2017-03-01Attackers compromise Deloitte's Azure admin account; gain access to global email system.
  2. 2017-09-25Deloitte publicly discloses the breach.

10Reaction and fallout

Public reaction

The breach caused significant concern among Deloitte's clients and raised questions about the security of Big Four accounting firms.

Political impact

Governments and regulators reviewed their relationships with Deloitte and other consulting firms.

Geopolitical consequences

The breach highlighted the espionage risk posed by compromised credentials at firms with access to sensitive global economic and government data.

11Legal

Deloitte faced investigations by UK and US regulators.

Civil lawsuits

  • Potential client lawsuits for breach of confidentiality

12Aftermath

Policy changes

  • Increased scrutiny of professional services firms' cybersecurity.

Security improvements

  • Deloitte implemented multi-factor authentication globally.
  • Enhanced monitoring of administrator accounts.

13Significance and legacy

Significance

The Deloitte hack demonstrated that the world's largest professional services firms were vulnerable to credential-based attacks and highlighted the downstream risk to their clients.

Legacy

The incident led to the widespread adoption of multi-factor authentication across the professional services industry.

14Disclosure and media

Authentication
Deloitte corporate disclosure

Media partners

  • The Guardian

Publishing organisations

  • Deloitte

15Field notes

  1. 01A single compromised administrator account was the gateway to the entire global email system.
  2. 02Deloitte had been urging its own clients to improve cybersecurity while its own systems were compromised.

16Resolution

Deloitte secured its email platform, implemented MFA, and notified affected clients.

17Sources

Official documents

  • Deloitte statement (Sept 2017)

References

  1. [1]The Guardian reporting (2017)
  2. [2]Deloitte corporate statement
Fact sheetEL-0199

Dates

Event
25 Sept 2017
Started
1 Mar 2017
Ended
25 Sept 2017
Duration
210 days
Discovered
25 Sept 2017
Disclosed
25 Sept 2017
Ongoing
No

Target

Organisation
Deloitte Touche Tohmatsu Limited
Type
Corporation
Sector
Professional Services / Consulting
Country
United Kingdom

Actor

Motivation
Industrial espionage; targeting of a Big Four accounting firm's global network of clients.
Attribution
Low
Arrested
No
Convicted
No

Data

Volume
350,000+ client emails and attachments
Sensitivity
Top Secret
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.