22 ms·
TSMC faces $70M ransom demand following lockbit cyberattack
- s3p 3y ago>this incident could potentially disrupt the supply of semiconductors and impact GPU prices. The global chip shortage has already led to increased prices and limited availability of GPUs. A disruption at TSMC could exacerbate this issue, potentially leading to further price hikes in the market for GPUs. This is a non-sequitr. Yes there was a cyberattack, but you presented no evidence as to how this could affect chip production besides giving a bunch of anecdotes to what a disruption would do. The rest of the article is informative but I just didn't understand this part.
- ttyprintk 3y agoA way of explaining the motivation of such an attack, without saying that a chip disruption would help the struggling Russian state.
- mynonameaccount 3y agoSounds like Kinmax Technologies owes TSMC 70M
- dirtyid 3y agoThat seems like a lot. Is this in line with ransom levels demanded in these attacks?
- rpaddock 3y agoAt least three of their Annual Reports indicates they knew of the risk of attack. Has there been any Ransomware Attacks that don't involve Windows machines? "Risks Associated with Cyber Attacks Even though TSMC has established a comprehensive internet and computing security network, it cannot guarantee that the Company’s computing systems which control or maintain vital corporate functions ,such as its manufacturing operations and enterprise accounting, would be completely immune to crippling cyber attacks by any third party to gain unauthorized access to its internal network systems, to sabotage its operations and goodwill or otherwise. In the event of a serious cyber attack, TSMC’s systems may lose important corporate data and its production lines may be shutdown indefinitely pending the resolution of such attack. While TSMC also seeks to annually review and assess its cybersecurity policies and procedures to ensure their adequacy and effectiveness, it cannot guarantee that the Company will not be susceptible to new and emerging risks and attacks in the evolving landscape of cybersecurity threats. These cyber attacks may also attempt to steal TSMC’s trade secrets and other intellectual properties and other sensitive information, such as proprietary information of the Company’s customers and other stakeholders and personal information of the Company’s employees. Malicious hackers may also try to introduce computer viruses, corrupted software or ransomware into the Company’s network systems to disrupt its operations, blackmail it for regaining control of its computing systems or spy for sensitive information. These attacks may result in TSMC having to pay damages for its delayed or disrupted orders or incur significant expenses in implementing remedial and improvement measures to enhance the Company’s cybersecurity network, and may also expose the Company to significant legal liabilities arising from or related to legal proceedings or regulatory investigations associated with, among other things, leakage of customer or third party information which TSMC has an obligation to keep confidential. During 2017 and as of the date of this Annual Report, the Company had not been aware of any material cyber attacks or incidents that had or would expected to have a material adverse effect on its business and operations, nor had it been involved in any legal proceedings or regulatory investigations related thereof. In addition, the Company employs certain third party service providers for TSMC and its affiliates worldwide with whom the Company needs to share highly sensitive and confidential information to enable them to provide the relevant services. Despite that TSMC requires the third party service providers to comply with the confidentiality and/or Internet security requirements in its service agreements with them, there is no assurance that each of them will strictly fulfill such obligations, or at all. The on-site network systems of and the off-site cloud computing networks such as servers maintained by such service provider and/or its contractors are also subject to risks associated with cyber attacks. If TSMC or its service providers are not able to timely resolve the respective technical difficulties caused by such cyber attacks, or ensure the integrity and availability of its data (and data belonging to its customers and other third parties) or control of its or its service providers’ computing systems, the Company’s commitments to its customers and other stakeholders may be materially impaired and its results of operations, financial condition, prospects and reputation may also be materially and adversely affected as a result." - https://investor.tsmc.com/static/annualReports/2017/english/pdf/e_11.pdf https://investor.tsmc.com/static/annualReports/2017/english/...
- indymike 3y agoFrom experience (was lead dev at company where sales let a bitlocker in and IT had mis-configured backup... which is normal for backup in most companies): It's all about what the infected machines can access. When my employer got hit, the problem was that there were many shared drives that the infected machines could access, and these were bitlockered. People would run programs off a shared drive, and get infected from that... then everything that machine had access to would get bitlockered. Backup was implemented where clients would push files to an open share and the share was backed up. The backups were bitlockered as a result. The shared drives were on a mix of linux and windows servers, and mac users that had shared folders the sales team could access had that data bitlockered. So, Windows was involved - it's how the bitlocker got in, but honestly, it was an emailed binary the salesperson ran that started the fun. Incidentally, the dev team (mix of Windows, Linux, Mac) was completely unaffected because we did not have any open shares, remote access was done with SSH. We used a backup system that ran as a pull, where the machine being backed up could not directly access the backup store, so safe. So yeah, Windows involved, but the damage was more about what infected machine had write access to on the network.
- api 3y agoThere have been ransomware attacks against vulnerable NAS devices, but yes it's mostly Windows. The biggest reason it's mostly Windows is not just worse security posture due to complexity but also that Windows is so popular in business, causing it to be the most aggressively attacked platform.
- wepple 3y agoI expect that to change over time. I personally expect man-in-the-browser attacks to start targeting SaaS application data. I suspect a secondary reason is that the way windows credentials and file shares are set up, you can really build one-size-fits-all malware that goes after creds and hashes in a fairly generic way.
- Grimburger 3y agoThere's a great Linux hardening guide that really made me question the common refrain about linux being more secure. Out of the box on many distros it's not particularly that safe, it's widespread usage in servers rather than desktops means it's more the sensible firewalling and lack of user installed apps that's giving it the appearance of security. Edit: the guide, first link is their rationale - https://madaidans-insecurities.github.io/guides/linux-hardening.html https://madaidans-insecurities.github.io/guides/linux-harden...
- ChoGGi 3y agoHuh, didn't expect to see TSMC in that headline.
- chasil 3y agoI patch every BMC that I can, but there are many that I can't. It just takes one. https://airbus-seclab.github.io/ilo/BHUSA2021-Slides-hpe_ilo_5_security_go_home_cryptoprocessor_youre_drunk-gazet_perigaud_czarny.pdf https://airbus-seclab.github.io/ilo/BHUSA2021-Slides-hpe_ilo...
- j_walter 3y agoWasn't really TSMC...but some info that was shared to Kinmax by TSMC. Totally different than TSMC being hacked directly...it's not like they hopped from Kinmax into TSMC's network either.
- DeathArrow 3y ago>LockBit targeted TSMC through one of its suppliers, Kinmax Technologies, an IT services provider specializing in networking, cloud computing, storage, security, and database management. The bit about security is ironic.
- vslira 3y ago> When asked why he robbed banks, Sutton simply replied, ‘Because that's where the money is.’
- ChuckNorris89 3y agoMost of these IT security & service providers are picked by the bean counters on the basis of "whichever is cheapest". When this is your selection bias, do the results surprise you?
- Proven 3y ago[dead]
- ensignavenger 3y agoOr who they play golf with.
- themoonisachees 3y agoNot really. The people picking the IT contractor are middle managers who spend all day in meetings. They don't play golf.
- zuppy 3y agomy experience is that usually this comes from CTO/director level and goes across the entire organization. middle managers don't have that much power, their role is just to spread (and watch) the requests across the teams.
- 3y ago
- sct202 3y ago>“Upon review, this incident has not affected TSMC’s business operations, nor did it compromise any TSMC’s customer information. After the incident, TSMC has immediately terminated its data exchange with this concerned supplier in accordance with the Company’s security protocols and standard operating procedures,” the company’s spokesperson told Cybernews. https://cybernews.com/news/tsmc-data-breach-lockbit/ https://cybernews.com/news/tsmc-data-breach-lockbit/
- nonethewiser 3y agoI immediately think about what motivation China would have to do or not do something like this. As they get shut out of semiconductor technology and don’t actually have any real control over Taiwan, it seems like there is no downside other than not wanting to get caught.
- itsoktocry 3y ago>don’t actually have any real control over Taiwan I'm not sure what you mean by "in control", but they have their foot in the door of Taiwanese politics, and share a lot of common culture. They also live next door.
- throwaway2990 3y agoNo. They have 0 control in Taiwanese politics unless you consider interference having their foot in the door.
- pjc50 3y agoThey might be doing espionage, but ransomware for a mere $70m wouldn't be worth the negative attention it might draw. North Korea on the other hand use ransomware as one of their main ways of getting foreign currency.
- _kbh_ 3y agoChina is already hiring everyone they can from TSMC they have no need to ransomware them. What remains to be seen if the response (if any) to this. You tread a fine line when you threaten the worlds chip supply.
- alias_neo 3y agoI'm curious what the real goal is with demands like this. Surely, given the size of the demand, it is beyond the authority of TSMC to pay up, even _if_ they wanted to? I imagine governments and authorities with any sort of stake in what could possibly be done with such a sum of money (it's unlikely to be used for Good, right?) would have an oversized say in whether or not they are allowed to pay it? Is there recent precedent for ransoms of this size being paid? What kind of data could they actually have "stolen" that's worth TSMC paying up $70M, rather than just writing it off?
- 55555 3y agoFor bigcorps, the ransoms are often 20-30 million USD. One of these is probably paid every few days. TSMC can easily pay 70 and might.
- hardware2win 3y agoTSMC has most desired technology and knowledge of our time It is modern equivalent of "rocket science" decades ago
- flkenosad 3y agoSeriously. They might be the most valuable organization in the world to target for this sort of thing.
- deleted 3y ago[deleted]
- kortilla 3y agoAbsolutely not. Read “the chip wars”. It does a good deep dive into the relationships of all of these companies. TSMC is amazing but they didn’t invent nor build the EUV lithography machines that enable their processes.
- hardware2win 3y ago
- ngneer 3y ago"the leak of information related to server initial setup and configuration" How valuable can this be?
- drumhead 3y agoA cyber ransom demand at one of the most important companies in the world, a lynchpin of digital manufacturing is not reassuring at all. Can their security really be that bad?
- Veserv 3y agoYes. You would be hard pressed to find any company in the entire world that could prevent attackers with a mere $1M budget. Banks, power plants, car companys, cybersecurity companys, factorys, you name it, almost certainly less than $1M. In fact, probably under $100K, but $1M is a safe upper bound. At a $10M budget there are zero. In fact, no CISO I have ever heard from has ever said that is even possible for a perfect implementation (i.e. they have free reign to implement everything they want as long as it does not make the company non-functional, but they get to be judge, jury, and executioner in that analysis). So yeah, given “perfectly implemented” security a $70M ransom has a guaranteed 700% ROI, but in practice closer to a over 7000% ROI.
- lyu07282 3y agoI imagine many independent security researchers can live quite comfortably just selling 0days on the "free market".
- Veserv 3y agoNot really if you live in a high cost-of-living (HCOL) country. Vulnerability weaponization is a very globalized industry and sufficiently easy that there is a oversupply from LCOL countrys. The real money is in deployment and usage as that requires the much rarer and more local criminal and money laundering skill sets.
- _kbh_ 3y ago> Not really if you live in a high cost-of-living (HCOL) country. Vulnerability weaponization is a very globalized industry and sufficiently easy that there is a oversupply from LCOL countrys. The real money is in deployment and usage as that requires the much rarer and more local criminal and money laundering skill sets. A single iOS or Android full chain still goes for between, 2-2.5 million USD. https://zerodium.com/images/zerodium_prices_mobiles.png https://zerodium.com/images/zerodium_prices_mobiles.png https://zerodium.com/images/zerodium_prices.png https://zerodium.com/images/zerodium_prices.png if someone was skilled they could easily live in a HCOL area making 1-1.25 million USD a year.
- yafbum 3y agoHow can these ransomware actors hide for so long? Is this all dependent on Bitcoin laundering?
- tough 3y agoif you're a government sanctioned NK actor you don't have to really hide you go to work to your govt office like it's tuesday and that's it
- deleted 3y ago[deleted]
- tux3 3y agoRansomware groups play a game of attacking the most valuable targets they can, without attracting so much attention that three letter friends start having meetings about them. Crypto is a necessary component. And then many ransomware implants will also refuse to run on systems with RUS locale, for instance. The understanding seems to be that groups can avoid attention of local law enforcement as long as they do not make any waves locally.
- pharrington 3y agoTSMC says they were not breached through Kinmax - only Kinmax was breached. https://www.bleepingcomputer.com/news/security/tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million/ https://www.bleepingcomputer.com/news/security/tsmc-denies-l...
- pksebben 3y agoCheers to you for providing updated context. This is why I come here.
- lkbm 3y agoAnyone else remember when Colonial Pipeline was attacked? The "ransomware as a service" platform[0] stepped in to say "oops, sorry, never mind" when they realized they'd attracted more attention than they were prepared for[1]: > We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives. > Our goal is to make money and not creating problems for society. > From today, we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future. This one isn't causing immediate disruptions to regular people in the US, but it's still geopolitical-level meddling. If you want to run around mugging people, it's best to avoid robbing the police chief's best friend. [0] https://www.state.gov/darkside-ransomware-as-a-service-raas/ https://www.state.gov/darkside-ransomware-as-a-service-raas/ [1] https://www.theverge.com/2021/5/10/22428996/colonial-pipeline-ransomware-attack-apology-investigation https://www.theverge.com/2021/5/10/22428996/colonial-pipelin...
- yborg 3y agoLockBit is Russian, they don't care about any of that, they are immune to external pressure as long as the current conflict is ongoing.
- wang_li 3y agoTSMC gets on the phone. Calls Vlad. Says, “It will be three hundred years before we sell an integrated circuit to any Russian entity unless you deliver to us the decryption keys, a complete description of everything on our network that was touched, and the thumbs of everyone involved. Hurry. If we recover from backups we’ll never need Russian language staff again, if you catch my drift.”
- newsclues 3y agoThey don’t care. They will source chips from China or other states they can use as puppets.
- rdsubhas 3y agoTarget and sanction the foreign assets and business channels of some politicians, and _they_ will react internally. Don't link everything to one ongoing conflict. Business interests continue unabated even in the darkest of times.
- traveler01 3y agoIf CIA and every world secret agency wasn't already after these people, they are now.
- fab30 3y agoAnyone got Twitter or something of national hazard agency where have they posted screenshots?
- fab30 3y agoAnyone got link of Twitter or something of national hazard agency where are they posting screenshots??
- varjag 3y agoRemember folks, don't use Windows in a professional setting.
- amelius 3y agoEven Linux's security model is a joke. Today I was asked to type my administrator password into a program called sdkmanager by Nvidia ...