Executive Summary
In June 2024, Japanese advertising conglomerate Dentsu disclosed a cybersecurity breach affecting its U.S.-based subsidiary, Merkle. Unauthorized attackers gained access to internal systems, resulting in the exposure of sensitive employee and client data. The incident was detected after suspicious activity was identified, prompting an immediate investigation and containment measures. While the full extent of the breach is under review, initial reports confirm that personally identifiable information and potentially business-critical records were compromised, highlighting gaps in east-west traffic security and egress controls within corporate IT infrastructure.
This incident demonstrates the continuing trend of cyberattacks against major marketing and advertising firms, which are prized for their troves of client data. Organizations are under mounting pressure to modernize east-west traffic security, enforce strict network segmentation, and rapidly detect post-compromise anomaly activity as threat actors increasingly target supply chain partners and professional services firms.
Why This Matters Now
The Dentsu Merkle breach is emblematic of rising threats facing professional service organizations with complex client data flows. As attackers leverage lateral movement and data exfiltration vectors, firms must urgently enhance segmentation, encryption, and anomaly response to protect sensitive data and comply with evolving regulatory demands.
Attack Path Analysis
The attacker likely gained initial access to Merkle's environment through credential compromise or exploitation of exposed cloud services. They escalated privileges by abusing weak IAM policies or misconfigured roles to extend their access. Movement across internal systems was enabled by insufficient east-west traffic controls, allowing the adversary to locate valuable staff and client data. Persistent command and control channels were established to maintain presence and exfiltrate data without detection. Sensitive data was exfiltrated—potentially over unencrypted outbound channels—to attacker-controlled locations. The impact materialized as exposure of personal and business data, with potential reputational and regulatory consequences for Dentsu and its subsidiary.
Kill Chain Progression
Initial Compromise
Description
Adversary obtains access via compromised credentials or exploitation of a misconfigured cloud resource (e.g., exposed API or management interface).
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Phishing
Application Layer Protocol
Remote Services
Account Discovery
Transfer Data to Cloud Account
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Identification and Authentication
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21(2)
CISA Zero Trust Maturity Model 2.0 – Strong Authentication and Least Privilege
Control ID: Identity Pillar - Authentication and Access Controls
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Marketing/Advertising/Sales
Direct impact from Dentsu-Merkle breach exposing client data requires enhanced east-west traffic security and zero trust segmentation to prevent lateral movement in advertising networks.
Information Technology/IT
Data breach highlights critical need for multicloud visibility, egress security policy enforcement, and encrypted traffic protection to safeguard client information across hybrid IT infrastructures.
Professional Training
Staff data exposure demonstrates vulnerability requiring threat detection capabilities, anomaly response systems, and comprehensive security awareness training to protect employee information and prevent similar incidents.
Sources
- Advertising giant Dentsu reports data breach at subsidiary Merklehttps://www.bleepingcomputer.com/news/security/advertising-giant-dentsu-reports-data-breach-at-subsidiary-merkle/Verified
- Dentsu's Merkle Hit By 'Cyber Incident,' Investigation Continueshttps://www.mediapost.com/publications/article/410229/dentsus-merkle-hit-by-cyber-incident-investiga.htmlVerified
- Data Security Incident | dentsuhttps://www.dentsu.com/uk/en/data-security-incidentVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Zero Trust segmentation, comprehensive east-west visibility, egress policy enforcement, and encrypted traffic controls would have restricted attacker movement, detected anomalies sooner, and prevented or minimized data exfiltration in Merkle’s breach.
Control: Zero Trust Segmentation
Mitigation: Restricts unauthorized access to sensitive workloads and management APIs.
Control: Multicloud Visibility & Control
Mitigation: Identifies and alerts on anomalous permission changes and policy violations.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized workload-to-workload and service-to-service traffic.
Control: Threat Detection & Anomaly Response
Mitigation: Detects and alerts on suspicious outbound communication patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized data exfiltration and unapproved outbound destinations.
Prevents attackers from reading or tampering with data in transit.
Impact at a Glance
Affected Business Functions
- Human Resources
- Finance
- Client Services
Estimated downtime: 3 days
Estimated loss: $5,000,000
The breach resulted in the exposure of sensitive information, including bank and payroll details, salary information, National Insurance numbers, and personal contact details of current and former employees, as well as data related to some clients and suppliers.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust segmentation and least privilege policies to strictly isolate sensitive cloud workloads and management interfaces.
- • Enable robust east-west traffic controls and continuous baselining to detect and stop unauthorized lateral movement.
- • Implement strong outbound egress filtering and centralized policy enforcement to prevent data exfiltration channels.
- • Ensure all sensitive data in transit is protected with high-performance encryption mechanisms (e.g., MACsec, IPsec).
- • Employ continuous multicloud visibility and threat anomaly detection to accelerate investigation and remediation of suspicious activities.



