
A former IBM cybersecurity executive has accused the company of concealing multiple breaches over several years, including incidents he says involved foreign state-linked hackers and affected IBM’s core network, subsidiaries and customer data. The allegations, contained in a lawsuit unsealed this week and originally filed in 2020, add a new layer of scrutiny to one of the world’s best-known technology and security vendors.
William Barlow, who served as IBM’s vice president of threat intelligence until August 2019, claims the company determined that Chinese hackers breached its core network between 2013 and 2016 and then failed to disclose the incidents. Barlow also alleges that at least two IBM subsidiaries were compromised and that those breaches were similarly covered up. Bloomberg first reported the lawsuit.
What Barlow alleges
According to the complaint, IBM’s core network was “routinely hacked by foreign state actors and others,” and stolen data was often not reported to government agencies. Barlow says the company did not alert authorities even after internal inquiries indicated the scope of the intrusion was significant.
The claims are especially notable because IBM is a major cybersecurity supplier to the U.S. federal government. That role makes any alleged concealment more consequential than a private-sector breach that remains undisclosed. In recent years, lawmakers have sought to strengthen breach disclosure requirements in part because incidents sometimes go unreported for years, if they are reported at all.
IBM, for its part, is pushing back. Company spokesperson Miki Carver declined to answer detailed questions about the allegations, but told TechCrunch: “This complaint was filed six years ago, and the U.S. Department of Justice declined to intervene. IBM is confident that our actions followed the letter of the law.”
APT 10 and the alleged core-network compromise
Barlow says IBM was among the victims of a hacking campaign attributed to APT 10, a Chinese government-linked group that then-FBI Director Christopher Wray described in 2018 as targeting a “Who’s Who” of the global economy. The group was publicly tied to a broad espionage operation after its members were indicted that year.
In the complaint, Barlow alleges the hackers gained access to IBM’s network and to data the company maintained in partnership with AT&T. He says the breach came to light after intelligence officials from the Five Eyes alliance — Australia, Canada, New Zealand, the United States and the United Kingdom — warned IBM about the intrusion in March 2017, prompting an internal investigation.
That investigation, according to the complaint, concluded that APT 10 may have breached IBM’s network more than 56,000 times between 2013 and 2016. The complaint says the company could not investigate more deeply because it had not retained logs showing who accessed its network and when. Barlow portrays that as a basic security failure that made it impossible to reconstruct the full scope of the compromise.
The complaint says IBM then failed to alert any authorities or the U.S. government, despite the fact that the company is one of the federal government’s major technology vendors. Barlow’s allegations suggest a disconnect between IBM’s public reputation as a cybersecurity leader and what he describes as shortcomings inside its own internal controls.
Internal findings described in the complaint
One of the more striking claims in the lawsuit is the description of IBM’s own internal investigation. Barlow cites an internal IBM report that, according to the complaint, found four servers were compromised in the APT 10 campaign. The same report allegedly said attackers had compromised and/or accessed nearly 400 compromised accounts and almost 200 total systems and servers across every IBM business unit, 18 countries and multiple IBM products.
The complaint also includes a stark assessment of IBM and AT&T’s infrastructure, describing their core networks as “archaic” and saying hackers had repeatedly gained access and could move through the systems “almost anywhere undetected.”
If accurate, those findings would indicate not just an isolated intrusion but a broader pattern of exposure across multiple parts of IBM’s operations. The company’s alleged inability to fully investigate because of missing logs is also central to Barlow’s case. In modern security practice, access logging is a foundational tool for detecting intrusion, tracing attacker movement and identifying what data may have been taken.
What IBM says in response
IBM has not addressed the allegations point by point, at least not publicly. Carver’s statement to TechCrunch focused on the procedural history of the lawsuit rather than the substance of the accusations. The company emphasized that the case was filed six years ago and said the Justice Department declined to intervene. IBM also said it is confident its actions complied with the law.
That response leaves open several important questions raised by the complaint, including what IBM knew, when it knew it, what internal reports concluded and why the company did not notify outside authorities if the breaches occurred as described. At this stage, however, the allegations remain allegations. The unsealed complaint reflects Barlow’s claims, not findings from a court.
Jason Brown, a lawyer representing Barlow, told TechCrunch his firm is “looking forward to aggressively litigating the matter.” Brown also argued that a company cannot sell cybersecurity services to the federal government while allegedly struggling with security failures inside its own organization.
Why the allegations matter
Even though the alleged incidents go back years, the case lands at a time when breach disclosure remains a major policy issue. Large organizations sometimes do not disclose cyber incidents immediately, and in some cases they never disclose them in a way that becomes public. That can leave customers, partners and government agencies operating without critical information about exposure and risk.
The IBM case is particularly sensitive because of the company’s role in government contracting. A vendor’s own security practices can become part of the trust equation when it handles systems or data for public agencies. If the allegations are proven, they would raise difficult questions about how a cybersecurity provider with such a profile managed internal risk and whether it fulfilled any legal reporting obligations.
The complaint also highlights a broader tension in cybersecurity: firms that advise others on defense may still fail to maintain the kinds of internal controls they recommend to customers. Logging, segmentation, incident detection and disclosure processes are ordinary expectations for mature security operations. Barlow’s allegations suggest IBM may have fallen short of those expectations in the very domain where it sells expertise.
The subsidiary breach claims
Beyond the core-network allegations, Barlow says two IBM subsidiaries were also breached and that those incidents were not properly disclosed. The source material identifies one of the affected businesses as Trusteer, a cybersecurity startup IBM acquired in 2013, which Barlow says was breached in 2018. He also points to Truven, a healthcare data startup IBM acquired in 2016, which he says was breached multiple times after the acquisition.
In both cases, he accuses IBM of failing to investigate thoroughly and of not informing relevant authorities or affected parties as required. The source material does not provide additional public detail on the mechanics of those alleged incidents, the types of data involved or whether any customer data was exposed. Still, the claims broaden the complaint beyond a single network compromise and suggest recurring issues across acquired businesses.
That pattern matters because acquisitions often bring together different technical environments, logging standards and security cultures. Integrating acquired companies securely is a known challenge, especially when one business is built around handling sensitive data. Barlow’s claims imply that IBM did not adequately unify or monitor those environments after the purchases.
What happens next
Because the complaint was unsealed this week after being filed in 2020, the case is only now gaining public attention. The Justice Department’s decision not to intervene does not end the matter; it simply means the government declined to join the action at the time. Barlow can still continue the litigation on his own through counsel.
The unsealing also means IBM will likely face renewed questions about internal security practices, its incident-response process and whether it retained the records necessary to understand what happened. Depending on how the case proceeds, the complaint could draw further scrutiny to the standards expected of large technology vendors that work with government clients.
For now, the most concrete facts are the ones in the source material: Barlow’s allegations, IBM’s denial of wrongdoing and the broader context of APT 10’s known activities. The court will determine how much of the complaint can be proven. Until then, the case stands as a reminder that some cyber incidents remain hidden for years, even when they involve some of the largest and most security-focused companies in the industry.
Source: Original report
Was this helpful?
Last Modified: July 7, 2026 at 8:44 pm
11 views

