Tuesday, July 4, 2023
Chipmaker TSMC said on Friday that one of its hardware suppliers experienced a “security incident” that allowed the attackers to obtain configurations and settings for some of the servers the company uses in its corporate network. The disclosure came a day after the LockBit ransomware crime syndicate listed TSMC on its extortion site and threatened to publish the data unless it received a payment of $70 million.
The hardware supplier, Kinmax Technology, confirmed that one of its test environments had been attacked by an external group, which was then able to retrieve configuration files and other parameter information. The company said it learned of the breach on Thursday and immediately shut down the compromised systems and notified the affected customer.
“Since the above information has nothing to do with the actual application of the customer, it is only the basic setting at the time of shipment,” Kinmax officials wrote. “At present, no damage has been caused to the customer, and the customer has not been hacked by it.”
In an email, a TSMC representative wrote, “Upon review, this incident has not affected TSMC’s business operations, nor did it compromise any TSMC’s customer information. After the incident, TSMC has immediately terminated its data exchange with this supplier in accordance with the Company’s security protocols and standard operating procedures.” The statement didn’t say if TSMC has been contacted by the attackers or if it plans to pay the ransom.
The statements came shortly after LockBit, one of the most active and pernicious ransomware groups, listed TSMC on its dark web site and demanded $70 million in exchange for deleting the data or transferring it to its rightful owner.
“In the case of payment refusal, also will be published points of entry into the network and passwords and logins company,” the post on the LockBit site said, using broken English that’s characteristic of the Russian-speaking group. “All available data will be published!”
By: DocMemory Copyright © 2023 CST, Inc. All Rights Reserved
|