01Summary
In September 2017, Deloitte disclosed that it had been the victim of a sophisticated cyberattack targeting its global email server. The attackers gained access to the Microsoft Azure-based email platform used by Deloitte's global workforce. The compromised data included emails and attachments from approximately 350,000 customers, containing highly sensitive information about client strategies, legal matters, and confidential business negotiations. The breach was discovered in March 2017 but was not publicly disclosed until September. Deloitte stated that only a small number of accounts were compromised but acknowledged that the attackers had 'deep' access to the system. The breach was particularly damaging because of Deloitte's role as an auditor and consultant to the world's largest corporations and governments.
02Background
Deloitte is one of the Big Four accounting firms, providing audit, tax, consulting, and financial advisory services to a vast global client base including many Fortune 500 companies and government agencies. The firm's access to highly sensitive client data made it a prime target for espionage.
03Key revelations
- 01A single compromised administrator account gave attackers access to Deloitte's entire global email system.
- 02The breach went undetected for approximately 6 months.
- 03The compromised data included highly sensitive client and government communications.
04Technical analysis
The attackers gained access using a compromised administrator account on Deloitte's Azure Active Directory. The single compromised credential allowed access to the entire global email system. The breach was discovered after anomalous login activity was detected.
- Attack vector
- Compromised administrator credentials
- Attack method
- Email account takeover via credential compromise
- Initial access
- Compromised credentials
- Exfiltration
- Email data extraction
Vulnerabilities exploited
- Weak or compromised administrator credentials
MITRE ATT&CK techniques
- T1078
05Threat actor
The perpetrator of the Deloitte hack has never been publicly identified. The sophistication of the attack suggested a well-resourced actor, possibly state-sponsored.
Attribution sources
- Deloitte Confirmation
- The Guardian
- Media Reports
06Victims and impact
Additional victims
- Deloitte Clients (including major corporations and governments)
Countries affected
- Global
07Data exposed
Data types
- Internal Emails
- Client Communications
- Strategic Documents
- Legal Correspondence
- Confidential Business Data
Notable documents
- Deloitte internal emails (accessed by attackers)
08Financial damage
Reputational damage, client trust erosion, potential legal liability.
09Timeline
- 2017-03-01Attackers compromise Deloitte's Azure admin account; gain access to global email system.
- 2017-09-25Deloitte publicly discloses the breach.
10Reaction and fallout
Public reaction
The breach caused significant concern among Deloitte's clients and raised questions about the security of Big Four accounting firms.
Political impact
Governments and regulators reviewed their relationships with Deloitte and other consulting firms.
Geopolitical consequences
The breach highlighted the espionage risk posed by compromised credentials at firms with access to sensitive global economic and government data.
11Legal
Deloitte faced investigations by UK and US regulators.
Civil lawsuits
- Potential client lawsuits for breach of confidentiality
12Aftermath
Policy changes
- Increased scrutiny of professional services firms' cybersecurity.
Security improvements
- Deloitte implemented multi-factor authentication globally.
- Enhanced monitoring of administrator accounts.
13Significance and legacy
Significance
The Deloitte hack demonstrated that the world's largest professional services firms were vulnerable to credential-based attacks and highlighted the downstream risk to their clients.
Legacy
The incident led to the widespread adoption of multi-factor authentication across the professional services industry.
14Disclosure and media
- Authentication
- Deloitte corporate disclosure
Media partners
- The Guardian
Publishing organisations
- Deloitte
15Field notes
- 01A single compromised administrator account was the gateway to the entire global email system.
- 02Deloitte had been urging its own clients to improve cybersecurity while its own systems were compromised.
16Resolution
Deloitte secured its email platform, implemented MFA, and notified affected clients.
17Sources
Official documents
- Deloitte statement (Sept 2017)
References
- [1]The Guardian reporting (2017)
- [2]Deloitte corporate statement









