Lockheed Martin's information security team detected the attack on Saturday 21 May 2011. Outside the company and the government agencies it briefed, nobody knew for four days. Then, on 25 May, the technology writer Robert X. Cringely published an account he had from a friend whose job was defending a large defence contractor's network. "Late on Sunday all remote access to the internal corporate network was disabled," the post said. "All workers were told was that it would be down for at least a week." Everyone holding an RSA SecurID token would be issued a new one over the following weeks, and everyone on the network — more than 100,000 people — would be asked to reset a password. Cringely withheld the company's name to limit the damage. Lockheed Martin employed about 126,000 people worldwide.
Reuters named the company on Friday 27 May, citing people familiar with the matter and an unnamed defence official. Lockheed declined to discuss specifics, and EMC, RSA's parent, would not discuss security issues affecting any particular customer. The company's own statement came on 28 May, a week after the detection, and ran four short paragraphs. "On Saturday, May 21, Lockheed Martin detected a significant and tenacious attack on its information systems network," it read. "As a result of the swift and deliberate actions taken to protect the network and increase IT security, our systems remain secure; no customer, program or employee personal data has been compromised." The team was working around the clock, it added, to restore employee access.
Lockheed never said in May what tied the shutdown to March. RSA had disclosed on 17 March that an extremely sophisticated intrusion had taken information related to SecurID, without saying what; researchers assumed the worst, which was the database mapping token serial numbers to their secret seeds. A token whose seed is known is a number anyone can compute. Northrop Grumman was reported to have cut remote access on 26 May; a memo to employees of L-3 Communications' Stratus group, obtained by Wired, said the company had been "actively targeted with penetration attacks leveraging the compromised information." Those were reports, not confirmations. The Pentagon's Lieutenant Colonel April Cunningham said the impact was "minimal and we don't expect any adverse effect"; Chris Ortman of the Department of Homeland Security said his agency and the Pentagon were helping establish the scope.
The confirmation, when it came, was in writing, and belonged to the next month. On 6 June 2011 RSA's executive chairman, Art Coviello, published an open letter to customers. "On Thursday, June 2, 2011, we were able to confirm that information taken from RSA in March had been used as an element of an attempted broader attack on Lockheed Martin, a major U.S. government defense contractor," it said, adding that the attack "does not reflect a new threat or vulnerability in RSA SecurID technology." RSA offered to replace tokens for customers whose concentrated user bases guarded intellectual property and corporate networks, and risk-based authentication for consumer-facing customers such as banks. The letter put no figure on the offer; press accounts reckoned it covered most of RSA's 25,000 client organisations, and RSA had long said some 40 million SecurID tokens were in use. What else June held is its own edition's business.
The database nobody was using
Sony had spent 1 May 2011 in Tokyo announcing a Welcome Back programme for the PlayStation Network, down since 20 April. The next day it disclosed a second intrusion, found while investigating the first. Personal details from about 24.6 million Sony Online Entertainment accounts might have been taken — name, address, email address, date of birth, gender, telephone number, login name and a hashed password — along with an outdated database last in use in 2007 that held roughly 12,700 non-US credit and debit card numbers with expiry dates but not security codes, and about 10,700 direct debit records belonging to customers in Austria, Germany, the Netherlands and Spain. The intrusion itself was dated to 16 and 17 April, Pacific time, overlapping the 17–19 April intrusion into the PlayStation Network that April's edition carries. Station.com went offline. Sony described the passwords only as hashed, naming neither the algorithm nor whether they were salted, and offered subscribers thirty days of play plus a day for each day the games were down. Phased restoration of the PlayStation Network began on 14 May, North America first.
A false story on The Rundown
Over the night of 29 and 30 May 2011 a group calling itself LulzSec put a story on The Rundown, the PBS NewsHour blog, reporting that the rapper Tupac Shakur — killed in 1996 — was alive in New Zealand, and Biggie Smalls with him. Defaced pages carried a graphic reading "All your base are belong to LulzSec" and a demand for the release of the soldier then awaiting court martial over the WikiLeaks disclosures. The stated grievance was the Frontline film WikiSecrets, broadcast days earlier; the group said it had watched it and been less than impressed. Anne Bentley, PBS's vice-president for corporate communications, said that "Last night there was an intrusion to PBS' servers" and that "The erroneous information on the PBS NewsHour site has been corrected," and that no personal information or email addresses of site visitors had been compromised. The group also published logins to two internal sites, the PBS PressRoom used by journalists and a communications site for member stations. The fifty days that followed belong to June.
Whose network it is
On 31 May 2011 the Department of Telecommunications amended the unified access service licence for security-related concerns; the other licence categories followed within days. Settled with the Ministry of Home Affairs, they moved the burden onto the operator. A licensee was made completely and totally responsible for the security of its own network. Networks were to be audited and certified by authorised agencies once a year. Network elements were to be tested against contemporary Indian or international security standards — ISO/IEC 15408 for information technology, the ISO 27000 series for security management, 3GPP for telecom elements — and from 1 April 2013 only in Indian laboratories. An operator whose inadequate precautions let an intrusion through could be fined up to 500 million rupees, then about eleven million dollars.
The amendment was also a retreat. A template issued in July 2010 had required foreign manufacturers to deposit source code and detailed designs in a government-controlled escrow account, to transfer their technology within three years and hand maintenance to Indian engineers within two — which vendors said amounted to giving the products away. May's version dropped both and put certification in their place. The office of the United States Trade Representative was reported to have welcomed the revision, which dropped the two demands American vendors had objected to most; ZTE was said to have accepted the guidelines, while Huawei had not decided. The laboratories took far longer than promised, the mandatory testing regime arriving in phases only at the end of the decade, and the argument over whose equipment could sit inside an Indian network never closed. An intrusion itself now has to be reported to CERT-In within six hours.
Robots that think on Google's servers
Google I/O, on 10 and 11 May 2011, included a session billed as Cloud Robotics. Ryan Hickman and Damon Kohler of Google, with Ken Conley and Brian Gerkey of Willow Garage, described a robot that keeps little on board: object recognition went to the servers behind Google Goggles, mapping and navigation to the cloud, and an Android phone became the controller. They announced rosjava, a Java version of the Robot Operating System so that Android devices could drive any ROS robot. The speech demonstration came in the Chrome keynote rather than Android's: Ian Ellison-Taylor spoke a welcome to San Francisco into Google Translate and heard it back in Chinese. On 26 May Google said its free Translate API would be shut off on 1 December, citing "substantial economic burden caused by extensive abuse"; within days it relented, promising a paid one. The borrowed brain outlasted the programme: Google rebuilt its robotics effort more than once, closing Everyday Robots in 2023, and its robots now run on the same kind of large models as its chatbots.
Mac Defender forces Apple's hand
Intego reported it on 2 May 2011: a fake anti-virus called Mac Defender, reached through poisoned Google image searches, selling cures for invented infections; Mac Protector and Mac Security followed, then from 25 May a Mac Guard needing no administrator password. An internal AppleCare document, updated on 16 May and leaked to ZDNet, told staff they "should not confirm or deny" an infection, nor help remove one. On 24 May Apple published a support note calling the campaign a phishing scam and promising an update within days. Security Update 2011-003 followed on 31 May, adding a Mac Defender definition to File Quarantine's malware check, daily definition updates and removal of known variants, on Snow Leopard only; a fresh variant slipped past within a day. That daily check is the ancestor of the scanning macOS still does; Flashback was eleven months off. Elsewhere Sophos agreed on 6 May to buy Astaro, a unified threat management vendor from Karlsruhe, on undisclosed terms, and Symantec on 19 May to pay about $390 million for the eDiscovery firm Clearwell Systems.
⏳ Time capsule — May 2011
- In the early hours of 2 May, Pakistan time, United States special operations forces killed Osama bin Laden at a compound in Abbottabad; the White House announced it hours later.
- On 25 May NASA ended its attempts to contact the Mars rover Spirit, which had last been heard from on 22 March 2010 and had worked 2,208 sols against a planned mission of ninety.
- Also on 25 May the last episode of The Oprah Winfrey Show was broadcast, the 4,561st across twenty-five seasons since national syndication began on 8 September 1986.
- On 28 May Barcelona beat Manchester United 3–1 at Wembley in front of 87,695 people to win the Champions League, Pedro, Lionel Messi and David Villa scoring against a reply from Wayne Rooney.
The month the second factor failed
EMC put the cost of investigating the RSA breach, hardening its systems and monitoring customers' transactions at $66.3 million, and the replacement tokens went out. What did not go out was an account of it. The executives who ran the response had signed ten-year non-disclosure agreements, and only when those expired in 2021 did they describe the night an analyst watched seed records leaving a server over nine hours and reached the delete command seconds too late — while Coviello told the same reporter he did not think the Lockheed attack had been related to RSA at all, and that it was never confirmed the intruders had taken the full list of seeds intact. That reporting placed the intruders in the People's Liberation Army unit a security firm named publicly in February 2013. No government published an attribution at the time.
The defence generalised better than the attack. Lockheed Martin's own answer appeared that year: Eric Hutchins, Michael Cloppert and Rohan Amin set out an intrusion kill chain of seven phases — reconnaissance, weaponisation, delivery, exploitation, installation, command and control, actions on objective — and gave a generation of defenders its vocabulary, along with the criticism that it stopped at the perimeter and ignored insiders. The shared secret held in a vendor's warehouse did not survive; what replaced it was a private key that never leaves the device, standardised by browsers late in the decade and shipped as passkeys in 2022. Sony's bill arrived in January 2013: a £250,000 fine from Britain's Information Commissioner's Office, which said the attack could have been prevented. LulzSec's run ended in June; the cooperation that broke it was revealed the following year.