the RSA SecurID breach (2011)
loresecuritycryptography
The March 2011 intrusion at RSA Security in which attackers stole material relating to the SecurID two-factor tokens used by tens of thousands of organisations - reaching the company through a phishing email carrying a spreadsheet with a Flash exploit, opened from a junk folder.
Within months an intrusion attempt at Lockheed Martin was tied to the stolen material, and RSA replaced tokens for a large share of its customer base. It is the canonical supply-chain lesson: compromising one security vendor undermines every customer's authentication at once, and trust in a vendor is a dependency exactly like a library or a certificate authority. It also demonstrated that a company whose product is trust can survive the breach but not the silence - RSA's early reticence cost it more than the incident.
Also known as: securid seed theft, lockheed intrusion, 2011 apt