William Barlow, the former vice president of threat intelligence at IBM, alleges in a lawsuit made public Thursday, June 4, that IBM and AT&T repeatedly hid breaches of their computer systems by foreign hackers from the U.S. government in order to win and keep federal contracts.
The complaint, filed under seal in 2020 and still pending before a federal court in New York, contains allegations that have not been proven and that the companies have not substantiated.
According to the complaint, the two companies failed to disclose multiple intrusions over a period of years by attackers linked to foreign governments and made false assurances about the security of their systems to secure government business. Barlow, who held a senior cybersecurity role at IBM, says he had direct knowledge of the events he describes.
In the suit, Barlow claims he personally witnessed numerous breaches of IBM’s core network and was pressured by executives to soften internal reports and leave out details. He alleges he knew of specific instances in which IBM senior management “actively took steps to cover up and conceal” hacks from U.S. regulators and government clients.
The company has not addressed those specific claims publicly.
The complaint paints a picture of confusion inside the companies. It alleges the breaches were so large, and the networks so poorly designed, that neither IBM nor AT&T could determine exactly what data was taken, who took it, or whether information had been copied or altered.
If accurate, that would mean the companies could not fully account for the security of systems they were paid to protect.
The suit alleges that hackers backed by the Chinese government were involved in some of the intrusions.
The claim fits a broader pattern U.S. authorities have described in recent years. In 2018, the Department of Justice charged two alleged members of a Chinese hacking group accused of stealing data from companies and government agencies.
The attribution in Barlow’s complaint, however, remains an allegation that has not been tested in court.
The legal vehicle matters for understanding the business stakes.
Barlow’s case is a whistleblower lawsuit of the kind used to allege fraud against the federal government. The core theory is that by giving false assurances about cybersecurity while concealing breaches, the companies obtained and retained federal contracts they might not otherwise have won.
Cases like these can expose defendants to substantial financial penalties if the government joins them and the claims are proven.
The federal contracting stakes are significant for both companies.
IBM is a major provider of information-technology services to government agencies, while AT&T supplies telecommunications and network services across the public sector.
Allegations that sensitive government-facing systems were breached, and that the breaches were hidden, strike at the heart of those relationships and at the trust the government places in large contractors.
Both companies have faced documented breaches in recent years, separate from the specific allegations in the suit.
AT&T disclosed a data breach in 2024 that affected more than 70 million current and former customers.
IBM was among the organizations affected by the wide-ranging MOVEit file-transfer breach carried out by a Russian ransomware group, and in 2026 an Italian subsidiary of the company was breached in an attack security researchers linked to a Chinese group known as Salt Typhoon.
Those incidents are publicly known and are not the same as the concealment claims Barlow is making.
The allegations remain unproven, and whistleblower suits of this type often take years to resolve and can be dismissed.
IBM has navigated similar litigation before; a separate whistleblower case accusing the company of misleading a federal agency was dropped after roughly a decade of court battles.
Because Barlow’s complaint was filed under seal, the companies’ formal responses are part of the pending litigation rather than public statements, and the case has not reached a stage where the claims have been weighed by a court.
For investors and government clients, the suit raises questions that extend beyond the courtroom.
Large technology and telecommunications companies hold some of the most sensitive data and run some of the most critical systems in the country, and allegations that breaches were hidden from regulators touch on reputational, financial, and national-security concerns at once.
Whether the claims hold up will depend on what evidence emerges as the case proceeds.
For now, the lawsuit is an accusation by a former insider, not a finding of wrongdoing.
It places two of the country’s largest technology and telecommunications firms at the center of a dispute over how breaches are reported and over what the government was told about the security of the systems it pays them to run.
JBizNews Desk — Cybersecurity & Government Contracting
© JBizNews.com All Rights Reserved. Reproduction or distribution without written permission is prohibited.



