Case file · RSA SECURID 2011

The RSA SecurID hack of 2011: one spreadsheet from the junk folder

Published 2026-09-29 · 4 min read · Missing control: Isolate authentication secrets from corporate network

The company whose key-fob tokens guarded logins at banks, governments and defense contractors was breached in 2011 through a spreadsheet an employee fished out of the junk mail folder.[1] This case file covers how that one email led to stolen SecurID information, why a defense contractor said it paid the price, and the one control that would have kept the crown jewels out of reach.

What happened

RSA, the security division of EMC, made SecurID: small hardware tokens that show a new number every minute or so. Employees type that number with their password, so a stolen password alone is not supposed to be enough.[2] Large organizations issued the tokens by the tens of thousands.[2]

In March 2011, over two days, two small groups of RSA employees received phishing emails with the subject line "2011 Recruitment Plan" and a spreadsheet attached.[1] The company's filters had done their job and sent the messages to junk mail. But at least one employee retrieved the message and opened the file, and that was enough.[1]

RSA spotted the attack while it was in progress, but not before information related to SecurID had been taken.[1][2] The company did not publish a full inventory of what was lost.[2] In late May, Lockheed Martin detected an intrusion attempt on its own network, and in early June it said its investigation had concluded the RSA breach was a direct contributing factor.[2]

How they got in

The spreadsheet carried a hidden object that took advantage of a flaw in Adobe Flash that had not yet been fixed, a so-called zero-day, later catalogued as CVE-2011-0609.[1][3] Opening the file quietly installed a backdoor that gave the intruders remote control of the employee's computer.[1]

From that first foothold, the attackers went after more powerful accounts. They collected login details, worked their way up to administrator-level access, and gathered the data they wanted on internal servers before sending it out of the company in compressed, encrypted bundles.[1]

The hard part for RSA was what sat within reach. Press reports at the time raised the worry that the stolen material could include the secret seed values that make each token's numbers unique, or the records linking tokens to those seeds.[1] Anyone holding that information would be much closer to faking a token's code, which is exactly what the product was meant to prevent.

What it cost

The breach turned into a customer crisis. In an open letter, RSA's executive chairman, Art Coviello, said the attackers had been after security information to target the defense sector, not money or personal data.[2] After the Lockheed news, RSA offered to replace tokens for virtually every customer, with a focus on organizations protecting intellectual property, and offered extra fraud monitoring to banks with large, dispersed customer bases.[2]

Lockheed said it was replacing 45,000 SecurID tokens used by its employees, and RSA gave 45,000 new tokens to its own staff.[2] Reports at the time also said other defense contractors had been targeted using stolen SecurID information.[2] Beyond hardware, the real cost was trust: a product sold as the second lock on the door had to be re-issued because the keys to the lock had been kept too close to everyday email.

The missing control

The missing control: isolating authentication secrets from the corporate network. Information that could help defeat SecurID was reachable from ordinary office systems, the same systems where staff read email and opened attachments.

Phishing will always get through sometimes; here, even the junk filter could not save the day once a person rescued the message.[1] The damage depended on what the intruders could reach next. If the token secrets had lived on a separate, locked-down network with no path from staff workstations, and with tight, logged access for the handful of people who needed them, a single infected laptop would have been a bad week instead of a global token recall.

What to do in your business

Watch the case
The junk-mail spreadsheet that breached RSA SecurIDDrops 2026-12-26
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Register: RSA explains how attackers breached its systems
  2. Dark Reading: RSA offers SecurID token replacement for customers in wake of Lockheed hack
  3. Dark Reading: RSA SecurID attack began with Excel file rigged with Flash zero-day