
When a company that handles sensitive corporate data for hundreds of the world’s largest businesses gets hit by a cyberattack, you’d expect some transparency. What Alation offered instead was a carefully worded statement and a lot of silence.
According to TechCrunch, Alation confirmed the cyberattack on Thursday, days after quietly flagging an unspecified “incident” that caused “degraded availability” for some customers on Tuesday. That earlier disruption was reportedly resolved within an hour. But what actually happened? The company isn’t saying. No root cause. No customer count. No word on whether data was stolen.
Alation makes data cataloging software that enterprise customers use to search through massive amounts of internal files and data using natural language queries. In recent years, it has pushed further into AI, helping companies turn messy, scattered data into something usable. It claims to work with more than 500 global companies, including roughly half of the Fortune 1000. That’s a significant concentration of sensitive corporate information sitting in or connected to its systems.
The company’s official statement, delivered through an external PR representative, read: “Alation recently identified an isolated incident involving unauthorized activity in one of its systems. We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate.” The phrase “as appropriate” is doing a lot of heavy lifting there. Appropriate for whom, exactly?
For privacy-conscious observers, the gaps in this disclosure are the story. Alation has not confirmed whether it notified affected customers directly. It has not said whether any data was exfiltrated. Much of its infrastructure runs on Amazon Web Services, which raises questions about the scope of the intrusion and what cloud-stored data may have been exposed.
This attack doesn’t happen in isolation. It fits into a clear pattern of hackers going after companies that aggregate valuable corporate data on behalf of their clients. Earlier this month, multiple companies reported data thefts following a breach at European shipping giant Ceva Logistics. Financial firms and private equity companies have also reportedly been targeted in recent weeks. Attackers have figured out that hitting one data-rich intermediary can expose dozens of downstream victims.
That’s what makes Alation’s tight-lipped response so frustrating. Its customers can’t make informed decisions about their own risk if the company won’t tell them what was accessed, when, and how. Saying the investigation is “thorough” costs nothing. Actual disclosure costs something. So far, Alation is choosing the cheaper option.