07 February 2012

VeriSign SEC Report Reveals 2010 Data Breaches

VeriSign, the company responsible for the .com, .net and .gov domain spaces, acknowledged in a recent filing with the Securities and Exchange Commission that it was hacked several times in 2010. The company had not disclosed the incidents at the time they occurred.

The SEC recommended companies disclose any security issues that pose a risk for operations or incidents that can have material impact on the business.
"In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers," VeriSign reported in the quarterly filing.
The attackers successfully stole data during the breaches, and the company was "unable to assure" that the information was not or could not be used by the attackers. VeriSign claimed it has implemented new defensive measures to prevent similar incidents.
It also appears the security team hid the breaches from VeriSign senior management when they occurred in 2010, and were not reported up the chain of command until September 2011, according to the SEC filing. "The occurrences of the attacks were not sufficiently reported to the Company's management at the time they occurred for the purpose of assessing any disclosure requirements," VeriSign claimed.

