IBM Accused of Covering Up Three Foreign Government Hacks in Whistleblower Lawsuit

A former IBM cybersecurity executive has accused the company of being hacked three times by foreign governments during the mid-2010s and then concealing the breaches from authorities and the public. The lawsuit, filed in 2020 and unsealed in June 2026, was first reported by Bloomberg.

William Barlow, who served as IBM’s vice president of threat intelligence until August 2019, alleges in the complaint that Chinese hackers linked to the state-sponsored group APT 10 breached IBM’s core network between 2013 and 2016 — potentially more than 56,000 times, according to an internal IBM investigation. That investigation found roughly 400 compromised accounts and nearly 200 systems and servers affected across 18 countries and multiple IBM business units. The hackers also reportedly accessed data IBM maintained in partnership with AT&T.

Barlow says IBM was alerted to the breach in March 2017 by intelligence officials from the Five Eyes alliance — Australia, Canada, New Zealand, the United States, and the United Kingdom — prompting the internal review. He alleges IBM then failed to notify any U.S. government agencies despite being a major federal cybersecurity vendor. The complaint also states IBM could not fully investigate because it had not maintained basic network access logs.

Beyond the core network breach, Barlow accuses IBM of covering up separate incidents at two subsidiaries: Trusteer, a cybersecurity startup IBM acquired in 2013, which he says was breached in 2018; and Truven, a healthcare data company acquired in 2016, which he says was breached multiple times after acquisition.

IBM spokesperson Miki Carver told TechCrunch: “This complaint was filed six years ago, and the U.S. Department of Justice declined to intervene. IBM is confident that our actions followed the letter of the law.” The company declined to address specific allegations.

Barlow’s attorney, Jason Brown, said the firm intends to litigate aggressively, adding: “You can’t sell cybersecurity to the federal government while allegedly having these security problems within your own company.” The case highlights ongoing concerns about corporate disclosure of data breaches, an issue that has prompted several new breach notification laws in recent years.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top