TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

TSMC faces $70M ransom demand following lockbit cyberattack

188 pointsby iphone14proalmost 2 years ago

18 comments

lkbmalmost 2 years ago
Anyone else remember when Colonial Pipeline was attacked? The &quot;ransomware as a service&quot; platform[0] stepped in to say &quot;oops, sorry, never mind&quot; when they realized they&#x27;d attracted more attention than they were prepared for[1]:<p>&gt; We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives.<p>&gt; Our goal is to make money and not creating problems for society.<p>&gt; From today, we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.<p>This one isn&#x27;t causing immediate disruptions to regular people in the US, but it&#x27;s still geopolitical-level meddling. If you want to run around mugging people, it&#x27;s best to avoid robbing the police chief&#x27;s best friend.<p>[0] <a href="https:&#x2F;&#x2F;www.state.gov&#x2F;darkside-ransomware-as-a-service-raas&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.state.gov&#x2F;darkside-ransomware-as-a-service-raas&#x2F;</a><p>[1] <a href="https:&#x2F;&#x2F;www.theverge.com&#x2F;2021&#x2F;5&#x2F;10&#x2F;22428996&#x2F;colonial-pipeline-ransomware-attack-apology-investigation" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.theverge.com&#x2F;2021&#x2F;5&#x2F;10&#x2F;22428996&#x2F;colonial-pipelin...</a>
评论 #36536508 未加载
pharringtonalmost 2 years ago
TSMC says they were not breached through Kinmax - only Kinmax was breached.<p><a href="https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;tsmc-denies-l...</a>
评论 #36536033 未加载
DeathArrowalmost 2 years ago
&gt;LockBit targeted TSMC through one of its suppliers, Kinmax Technologies, an IT services provider specializing in networking, cloud computing, storage, security, and database management.<p>The bit about security is ironic.
评论 #36535840 未加载
评论 #36534391 未加载
评论 #36534368 未加载
alias_neoalmost 2 years ago
I&#x27;m curious what the real goal is with demands like this.<p>Surely, given the size of the demand, it is beyond the authority of TSMC to pay up, even _if_ they wanted to?<p>I imagine governments and authorities with any sort of stake in what could possibly be done with such a sum of money (it&#x27;s unlikely to be used for Good, right?) would have an oversized say in whether or not they are allowed to pay it?<p>Is there recent precedent for ransoms of this size being paid?<p>What kind of data could they actually have &quot;stolen&quot; that&#x27;s worth TSMC paying up $70M, rather than just writing it off?
评论 #36535114 未加载
评论 #36535575 未加载
评论 #36535265 未加载
评论 #36539874 未加载
评论 #36535932 未加载
评论 #36535120 未加载
sct202almost 2 years ago
&gt;“Upon review, this incident has not affected TSMC’s business operations, nor did it compromise any TSMC’s customer information. After the incident, TSMC has immediately terminated its data exchange with this concerned supplier in accordance with the Company’s security protocols and standard operating procedures,” the company’s spokesperson told Cybernews.<p><a href="https:&#x2F;&#x2F;cybernews.com&#x2F;news&#x2F;tsmc-data-breach-lockbit&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;cybernews.com&#x2F;news&#x2F;tsmc-data-breach-lockbit&#x2F;</a>
drumheadalmost 2 years ago
A cyber ransom demand at one of the most important companies in the world, a lynchpin of digital manufacturing is not reassuring at all. Can their security really be that bad?
评论 #36535881 未加载
评论 #36536205 未加载
s3palmost 2 years ago
&gt;this incident could potentially disrupt the supply of semiconductors and impact GPU prices. The global chip shortage has already led to increased prices and limited availability of GPUs. A disruption at TSMC could exacerbate this issue, potentially leading to further price hikes in the market for GPUs.<p>This is a non-sequitr. Yes there was a cyberattack, but you presented no evidence as to how this could affect chip production besides giving a bunch of anecdotes to what a disruption would do. The rest of the article is informative but I just didn&#x27;t understand this part.
评论 #36545692 未加载
ngneeralmost 2 years ago
&quot;the leak of information related to server initial setup and configuration&quot;<p>How valuable can this be?
评论 #36535701 未加载
评论 #36535551 未加载
traveler01almost 2 years ago
If CIA and every world secret agency wasn&#x27;t already after these people, they are now.
nonethewiseralmost 2 years ago
I immediately think about what motivation China would have to do or not do something like this. As they get shut out of semiconductor technology and don’t actually have any real control over Taiwan, it seems like there is no downside other than not wanting to get caught.
评论 #36535620 未加载
评论 #36535201 未加载
评论 #36535040 未加载
fab30almost 2 years ago
Anyone got link of Twitter or something of national hazard agency where are they posting screenshots??
yafbumalmost 2 years ago
How can these ransomware actors hide for so long? Is this all dependent on Bitcoin laundering?
评论 #36535856 未加载
评论 #36535805 未加载
评论 #36535819 未加载
fab30almost 2 years ago
Anyone got Twitter or something of national hazard agency where have they posted screenshots?
dirtyidalmost 2 years ago
That seems like a lot. Is this in line with ransom levels demanded in these attacks?
mynonameaccountalmost 2 years ago
Sounds like Kinmax Technologies owes TSMC 70M
rpaddockalmost 2 years ago
At least three of their Annual Reports indicates they knew of the risk of attack.<p>Has there been any Ransomware Attacks that don&#x27;t involve Windows machines?<p>&quot;Risks Associated with Cyber Attacks<p>Even though TSMC has established a comprehensive internet and computing security network, it cannot guarantee that the Company’s computing systems which control or maintain vital corporate functions ,such as its manufacturing operations and enterprise accounting, would be completely immune to crippling cyber attacks by any third party to gain unauthorized access to its internal network systems, to sabotage its operations and goodwill or otherwise. In the event of a serious cyber attack, TSMC’s systems may lose important corporate data and its production lines may be shutdown indefinitely pending the resolution of such attack. While TSMC also seeks to annually review and assess its cybersecurity policies and procedures to ensure their adequacy and effectiveness, it cannot guarantee that the Company will not be susceptible to new and emerging risks and attacks in the evolving landscape of cybersecurity threats. These cyber attacks may also attempt to steal TSMC’s trade secrets and other intellectual properties and other sensitive information, such as proprietary information of the Company’s customers and other stakeholders and personal information of the Company’s employees. Malicious hackers may also try to introduce computer viruses, corrupted software or ransomware into the Company’s network systems to disrupt its operations, blackmail it for regaining control of its computing systems or spy for sensitive information. These attacks may result in TSMC having to pay damages for its delayed or disrupted orders or incur significant expenses in implementing remedial and improvement measures to enhance the Company’s cybersecurity network, and may also expose the Company to significant legal liabilities arising from or related to legal proceedings or regulatory investigations associated with, among other things, leakage of customer or third party information which TSMC has an obligation to keep confidential. During 2017 and as of the date of this Annual Report, the Company had not been aware of any material cyber attacks or incidents that had or would expected to have a material adverse effect on its business and operations, nor had it been involved in any legal proceedings or regulatory investigations related thereof.<p>In addition, the Company employs certain third party service providers for TSMC and its affiliates worldwide with whom the Company needs to share highly sensitive and confidential information to enable them to provide the relevant services. Despite that TSMC requires the third party service providers to comply with the confidentiality and&#x2F;or Internet security requirements in its service agreements with them, there is no assurance that each of them will strictly fulfill such obligations, or at all. The on-site network systems of and the off-site cloud computing networks such as servers maintained by such service provider and&#x2F;or its contractors are also subject to risks associated with cyber attacks. If TSMC or its service providers are not able to timely resolve the respective technical difficulties caused by such cyber attacks, or ensure the integrity and availability of its data (and data belonging to its customers and other third parties) or control of its or its service providers’ computing systems, the Company’s commitments to its customers and other stakeholders may be materially impaired and its results of operations, financial condition, prospects and reputation may also be materially and adversely affected as a result.&quot; - <a href="https:&#x2F;&#x2F;investor.tsmc.com&#x2F;static&#x2F;annualReports&#x2F;2017&#x2F;english&#x2F;pdf&#x2F;e_11.pdf" rel="nofollow noreferrer">https:&#x2F;&#x2F;investor.tsmc.com&#x2F;static&#x2F;annualReports&#x2F;2017&#x2F;english&#x2F;...</a>
评论 #36534312 未加载
评论 #36534426 未加载
评论 #36539222 未加载
评论 #36535113 未加载
ChoGGialmost 2 years ago
Huh, didn&#x27;t expect to see TSMC in that headline.
评论 #36534406 未加载
评论 #36536966 未加载
varjagalmost 2 years ago
Remember folks, don&#x27;t use Windows in a professional setting.
评论 #36539798 未加载