The Containment Era is here. →Explore

Executive Summary

In June 2024, Japanese advertising conglomerate Dentsu disclosed a cybersecurity breach affecting its U.S.-based subsidiary, Merkle. Unauthorized attackers gained access to internal systems, resulting in the exposure of sensitive employee and client data. The incident was detected after suspicious activity was identified, prompting an immediate investigation and containment measures. While the full extent of the breach is under review, initial reports confirm that personally identifiable information and potentially business-critical records were compromised, highlighting gaps in east-west traffic security and egress controls within corporate IT infrastructure.

This incident demonstrates the continuing trend of cyberattacks against major marketing and advertising firms, which are prized for their troves of client data. Organizations are under mounting pressure to modernize east-west traffic security, enforce strict network segmentation, and rapidly detect post-compromise anomaly activity as threat actors increasingly target supply chain partners and professional services firms.

Why This Matters Now

The Dentsu Merkle breach is emblematic of rising threats facing professional service organizations with complex client data flows. As attackers leverage lateral movement and data exfiltration vectors, firms must urgently enhance segmentation, encryption, and anomaly response to protect sensitive data and comply with evolving regulatory demands.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident highlighted gaps relative to frameworks such as PCI DSS, HIPAA, and NIST 800-53, particularly in areas of data encryption, network segmentation, and event monitoring.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing Zero Trust segmentation, comprehensive east-west visibility, egress policy enforcement, and encrypted traffic controls would have restricted attacker movement, detected anomalies sooner, and prevented or minimized data exfiltration in Merkle’s breach.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Restricts unauthorized access to sensitive workloads and management APIs.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Identifies and alerts on anomalous permission changes and policy violations.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevents unauthorized workload-to-workload and service-to-service traffic.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Detects and alerts on suspicious outbound communication patterns.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocks unauthorized data exfiltration and unapproved outbound destinations.

Impact (Mitigations)

Prevents attackers from reading or tampering with data in transit.

Impact at a Glance

Affected Business Functions

  • Human Resources
  • Finance
  • Client Services
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

The breach resulted in the exposure of sensitive information, including bank and payroll details, salary information, National Insurance numbers, and personal contact details of current and former employees, as well as data related to some clients and suppliers.

Recommended Actions

  • Deploy Zero Trust segmentation and least privilege policies to strictly isolate sensitive cloud workloads and management interfaces.
  • Enable robust east-west traffic controls and continuous baselining to detect and stop unauthorized lateral movement.
  • Implement strong outbound egress filtering and centralized policy enforcement to prevent data exfiltration channels.
  • Ensure all sensitive data in transit is protected with high-performance encryption mechanisms (e.g., MACsec, IPsec).
  • Employ continuous multicloud visibility and threat anomaly detection to accelerate investigation and remediation of suspicious activities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image