• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

GIGABYTE Hacked, Attackers Threaten to Leak Confidential Intel, AMD, AMI Documents

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
47,297 (7.53/day)
Location
Hyderabad, India
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard ASUS ROG Strix B450-E Gaming
Cooling DeepCool Gammax L240 V2
Memory 2x 8GB G.Skill Sniper X
Video Card(s) Palit GeForce RTX 2080 SUPER GameRock
Storage Western Digital Black NVMe 512GB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
PC components major GIGABYTE has reportedly been hacked, with the attacker group, which goes by the name RansomEXX, stealing 112 GB in data that contains confidential technical documents from Intel, AMD, and others; which are released to GIGABYTE under strict NDAs, to help it design motherboards, notebooks, desktops, servers, and graphics cards. The group also deployed ransomware to encrypt GIGABYTE's data, which includes these documents. The attack allegedly occurred in the week of August 2, and GIGABYTE was forced to shut down its systems in its Taiwan headquarters. This even caused some downtime for its websites.

While it's conceivable that a company of GIGABYTE's scale would maintain timely cold backups of its data, and can recover almost everything RansomEXX encrypted, there's another aspect to this attack, and it's the data the attackers stole. They threaten to leak the data if a ransom isn't paid in time. This would put a large amount of confidential documents, including motherboard designs, UEFI/BIOS/TPM data/keys, etc., out in the public domain. GIGABYTE didn't comment on the issue beyond stating that it has isolated the affected servers from the rest of its network and notified law enforcement.



View at TechPowerUp Main Site
 
Joined
Feb 18, 2013
Messages
2,186 (0.51/day)
Location
Deez Nutz, bozo!
System Name Rainbow Puke Machine :D
Processor Intel Core i5-11400 (MCE enabled, PL removed)
Motherboard ASUS STRIX B560-G GAMING WIFI mATX
Cooling Corsair H60i RGB PRO XT AIO + HD120 RGB (x3) + SP120 RGB PRO (x3) + Commander PRO
Memory Corsair Vengeance RGB RT 2 x 8GB 3200MHz DDR4 C16
Video Card(s) Zotac RTX2060 Twin Fan 6GB GDDR6 (Stock)
Storage Corsair MP600 PRO 1TB M.2 PCIe Gen4 x4 SSD
Display(s) LG 29WK600-W Ultrawide 1080p IPS Monitor (primary display)
Case Corsair iCUE 220T RGB Airflow (White) w/Lighting Node CORE + Lighting Node PRO RGB LED Strips (x4).
Audio Device(s) ASUS ROG Supreme FX S1220A w/ Savitech SV3H712 AMP + Sonic Studio 3 suite
Power Supply Corsair RM750x 80 Plus Gold Fully Modular
Mouse Corsair M65 RGB FPS Gaming (White)
Keyboard Corsair K60 PRO RGB Mechanical w/ Cherry VIOLA Switches
Software Windows 11 Professional x64 (Update 23H2)
when you think that scalping and mining isn't making enough money... good luck to those guys when SWAT comes knocking on their doors.
 
Joined
Feb 18, 2013
Messages
2,186 (0.51/day)
Location
Deez Nutz, bozo!
System Name Rainbow Puke Machine :D
Processor Intel Core i5-11400 (MCE enabled, PL removed)
Motherboard ASUS STRIX B560-G GAMING WIFI mATX
Cooling Corsair H60i RGB PRO XT AIO + HD120 RGB (x3) + SP120 RGB PRO (x3) + Commander PRO
Memory Corsair Vengeance RGB RT 2 x 8GB 3200MHz DDR4 C16
Video Card(s) Zotac RTX2060 Twin Fan 6GB GDDR6 (Stock)
Storage Corsair MP600 PRO 1TB M.2 PCIe Gen4 x4 SSD
Display(s) LG 29WK600-W Ultrawide 1080p IPS Monitor (primary display)
Case Corsair iCUE 220T RGB Airflow (White) w/Lighting Node CORE + Lighting Node PRO RGB LED Strips (x4).
Audio Device(s) ASUS ROG Supreme FX S1220A w/ Savitech SV3H712 AMP + Sonic Studio 3 suite
Power Supply Corsair RM750x 80 Plus Gold Fully Modular
Mouse Corsair M65 RGB FPS Gaming (White)
Keyboard Corsair K60 PRO RGB Mechanical w/ Cherry VIOLA Switches
Software Windows 11 Professional x64 (Update 23H2)
don't think so.
 
Joined
Feb 23, 2019
Messages
6,105 (2.87/day)
Location
Poland
Processor Ryzen 7 5800X3D
Motherboard Gigabyte X570 Aorus Elite
Cooling Thermalright Phantom Spirit 120 SE
Memory 2x16 GB Crucial Ballistix 3600 CL16 Rev E @ 3600 CL14
Video Card(s) RTX3080 Ti FE
Storage SX8200 Pro 1 TB, Plextor M6Pro 256 GB, WD Blue 2TB
Display(s) LG 34GN850P-B
Case SilverStone Primera PM01 RGB
Audio Device(s) SoundBlaster G6 | Fidelio X2 | Sennheiser 6XX
Power Supply SeaSonic Focus Plus Gold 750W
Mouse Endgame Gear XM1R
Keyboard Wooting Two HE
Don't pay, nuke them from orbit.
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,964 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
Such a leak would be awesome for the developer community, to better support existing hardware
 
Joined
Feb 11, 2009
Messages
5,570 (0.96/day)
System Name Cyberline
Processor Intel Core i7 2600k -> 12600k
Motherboard Asus P8P67 LE Rev 3.0 -> Gigabyte Z690 Auros Elite DDR4
Cooling Tuniq Tower 120 -> Custom Watercoolingloop
Memory Corsair (4x2) 8gb 1600mhz -> Crucial (8x2) 16gb 3600mhz
Video Card(s) AMD RX480 -> RX7800XT
Storage Samsung 750 Evo 250gb SSD + WD 1tb x 2 + WD 2tb -> 2tb MVMe SSD
Display(s) Philips 32inch LPF5605H (television) -> Dell S3220DGF
Case antec 600 -> Thermaltake Tenor HTCP case
Audio Device(s) Focusrite 2i4 (USB)
Power Supply Seasonic 620watt 80+ Platinum
Mouse Elecom EX-G
Keyboard Rapoo V700
Software Windows 10 Pro 64bit
always love reading these sorta emails, what a bunch of muppets
 
Joined
Jun 4, 2019
Messages
56 (0.03/day)
Looking at Gigabytes recent history leads you to believe that their security measures aren't up to par. I'd be very surprised if they were.

Would the general public benefit from such leaks? Given the size of the industry and nearly non existent competition (Intel VS AMD), I'd think so. If yes, fingers crossed. Gigabyte might learn a lesson in security and quality assurance that they desperately need. Or maybe they won't.
 
Joined
May 12, 2017
Messages
2,207 (0.79/day)
when you think that scalping and mining isn't making enough money... good luck to those guys when SWAT comes knocking on their doors.

A single hacker may get caught but a team of hackers will never get caught. They will always be one step ahead.
 

PiusX

New Member
Joined
Aug 10, 2021
Messages
1 (0.00/day)
A few months ago someone at Gigabyte (they attributed an intern) screwed up and phrased things on the Gigabyte China website that implied Made in China = sub-par quality. The response was immediate and draconian: all online sales were banned for two months on all major online platforms and websites in China. They returned just last month. Even today when you first arrive at the Gigabyte China website a pop up appears reiterating their Mea Culpa. I would be powerfully surprised if RansomEXX were not Mainland China based.
 
Joined
Jan 28, 2012
Messages
468 (0.10/day)
Location
Lithuania
Processor Intel Core i5 4670K @ 4.8 GHz
Motherboard AsRock Z87 Extreme 4
Cooling Lepa NeoIllusion RGB CPU cooler
Memory 2*4GB Patriot G2 Series RAM
Video Card(s) MSI Radeon R9 380 4GB
Storage Transcend SSD 740 256GB + WD Caviar Blue 1TB
Display(s) Samsung SA 300 24" Full HD
Case NZXT Phantom 530 + Bitfenix Recon fan controller
Audio Device(s) Creative SB0770 X-Fi Xtreme Gamer
Power Supply PC Power and Cooling Silencer MkIII 750W 80+ Gold
Mouse Logitech G502
Keyboard Steelseries Apex RAW
Benchmark Scores IT WORKS
I had "hacked" Silverstone and Enermax websites some years ago. All their products had their product id (id=420 for example) in their product page link. If I add +1 to their latest product (id=421 for example) unrelised product appears. The most interesting thing is that some products weren't relised in retail market.

Conclusion - cyber secturity in some companies are terific. As far I know Enermax and Silverstone updated their websites.
 
Joined
Jul 6, 2008
Messages
35 (0.01/day)
Gigabyte is probably faking this, they just didn't want people sending in emails after the last Gamers Nexus video.
 
Joined
Nov 25, 2019
Messages
825 (0.44/day)
Location
Taiwan
Processor i5-9600K
Motherboard Gigabyte Z390 Gaming X
Cooling Scythe Mugen 5S
Memory Micron Ballistix Sports LT 3000 8G*4
Video Card(s) EVGA 3070 XC3 Ultra Gaming
Storage Adata SX6000 Pro 512G, Kingston A2000 1T
Display(s) Gigabyte M32Q
Case Antec DF700 Flux
Audio Device(s) Edifier C3X
Power Supply Super Flower Leadex Gold 650W
Mouse Razer Basilisk V2
Keyboard Ducky ONE 2 Horizon
I'm kind of surprised that I didn't even see any news about this even in Taiwan.
 
Joined
Feb 23, 2019
Messages
6,105 (2.87/day)
Location
Poland
Processor Ryzen 7 5800X3D
Motherboard Gigabyte X570 Aorus Elite
Cooling Thermalright Phantom Spirit 120 SE
Memory 2x16 GB Crucial Ballistix 3600 CL16 Rev E @ 3600 CL14
Video Card(s) RTX3080 Ti FE
Storage SX8200 Pro 1 TB, Plextor M6Pro 256 GB, WD Blue 2TB
Display(s) LG 34GN850P-B
Case SilverStone Primera PM01 RGB
Audio Device(s) SoundBlaster G6 | Fidelio X2 | Sennheiser 6XX
Power Supply SeaSonic Focus Plus Gold 750W
Mouse Endgame Gear XM1R
Keyboard Wooting Two HE
A single hacker may get caught but a team of hackers will never get caught. They will always be one step ahead.
Until one of them squeal. And they always do!
Those hackers are most probably operating from China or Russia. Good luck catching them. If they're from Russia - no problems from officials until they attack one of the allied states/companies. If they're from China - no problems because it's a company from Taiwan.

Gigabyte will probably do what everyone else does - "support" deal with IT security company that will then pay ransom and decode the files.
 
Joined
Sep 10, 2015
Messages
530 (0.16/day)
System Name My Addiction
Processor AMD Ryzen 7950X3D
Motherboard ASRock B650E PG-ITX WiFi
Cooling Alphacool Core Ocean T38 AIO 240mm
Memory G.Skill 32GB 6000MHz
Video Card(s) Sapphire Pulse 7900XTX
Storage Some SSDs
Display(s) 42" Samsung TV + 22" Dell monitor vertically
Case Lian Li A4-H2O
Audio Device(s) Denon + Bose
Power Supply Corsair SF750
Mouse Logitech
Keyboard Glorious
VR HMD None
Software Win 10
Benchmark Scores None taken
Don't pay, nuke them from orbit.

They can't pay because they can't have any kind of insurance the files will not be used anyway on the othet side. If it were possible to have that kind of insurance, they might...

I had "hacked" Silverstone and Enermax websites some years ago. All their products had their product id (id=420 for example) in their product page link. If I add +1 to their latest product (id=421 for example) unrelised product appears. The most interesting thing is that some products weren't relised in retail market.

Conclusion - cyber secturity in some companies are terific. As far I know Enermax and Silverstone updated their websites.

Oh, yes... Cybersecurity... An invisible thing that eats up a lot of money and returns none of it... Until it would...
 
Joined
Mar 20, 2019
Messages
556 (0.26/day)
Processor 9600k
Motherboard MSI Z390I Gaming EDGE AC
Cooling Scythe Mugen 5
Memory 32GB of G.Skill Ripjaws V 3600MHz CL16
Video Card(s) MSI 3080 Ventus OC
Storage 2x Intel 660p 1TB
Display(s) Acer CG437KP
Case Streacom BC1 mini
Audio Device(s) Topping MX3
Power Supply Corsair RM750
Mouse R.A.T. DWS
Keyboard HAVIT KB487L / AKKO 3098 / Logitech G19
VR HMD HTC Vive
Benchmark Scores What's a "benchmark"?
I honestly can't feel bad for corporate drones. If it involved consumer data it might be an actual problem, but corporate rubbish... whatever, let them burn.
 
Joined
Jul 10, 2017
Messages
2,671 (0.98/day)
They can't pay because they can't have any kind of insurance the files will not be used anyway on the othet side. If it were possible to have that kind of insurance, they might...



Oh, yes... Cybersecurity... An invisible thing that eats up a lot of money and returns none of it... Until it would...
Decent security helps you win money by not letting you lose it. The more money you put in security, the less you lose from attacks.

The real deal is striking the perfect balance, so that all risks are identified and accounted for.

Gigabyte is probably faking this, they just didn't want people sending in emails after the last Gamers Nexus video.
What happened there?
 
Joined
Feb 23, 2019
Messages
6,105 (2.87/day)
Location
Poland
Processor Ryzen 7 5800X3D
Motherboard Gigabyte X570 Aorus Elite
Cooling Thermalright Phantom Spirit 120 SE
Memory 2x16 GB Crucial Ballistix 3600 CL16 Rev E @ 3600 CL14
Video Card(s) RTX3080 Ti FE
Storage SX8200 Pro 1 TB, Plextor M6Pro 256 GB, WD Blue 2TB
Display(s) LG 34GN850P-B
Case SilverStone Primera PM01 RGB
Audio Device(s) SoundBlaster G6 | Fidelio X2 | Sennheiser 6XX
Power Supply SeaSonic Focus Plus Gold 750W
Mouse Endgame Gear XM1R
Keyboard Wooting Two HE
What happened there?
In GN testing 50% of the PSU's that Newegg shoved down people's throat with GPU's went kaboom.

It's either bad design, bad components due to component shortages or a mix of both.
 
Joined
Jul 10, 2017
Messages
2,671 (0.98/day)
In GN testing 50% of the PSU's that Newegg shoved down people's throat with GPU's went kaboom.

It's either bad design, bad components due to component shortages or a mix of both.
Holly... :fear:
 

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
17,769 (2.42/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/yfsd9w
I'm kind of surprised that I didn't even see any news about this even in Taiwan.
I think they want to keep it quiet. It's most likely highly embarrassing for them and losing face is just not something you do...

Those hackers are most probably operating from China or Russia. Good luck catching them. If they're from Russia - no problems from officials until they attack one of the allied states/companies. If they're from China - no problems because it's a company from Taiwan.

Gigabyte will probably do what everyone else does - "support" deal with IT security company that will then pay ransom and decode the files.
They're not going to pay the ransom from what I've heard.
 
Joined
Jan 28, 2012
Messages
468 (0.10/day)
Location
Lithuania
Processor Intel Core i5 4670K @ 4.8 GHz
Motherboard AsRock Z87 Extreme 4
Cooling Lepa NeoIllusion RGB CPU cooler
Memory 2*4GB Patriot G2 Series RAM
Video Card(s) MSI Radeon R9 380 4GB
Storage Transcend SSD 740 256GB + WD Caviar Blue 1TB
Display(s) Samsung SA 300 24" Full HD
Case NZXT Phantom 530 + Bitfenix Recon fan controller
Audio Device(s) Creative SB0770 X-Fi Xtreme Gamer
Power Supply PC Power and Cooling Silencer MkIII 750W 80+ Gold
Mouse Logitech G502
Keyboard Steelseries Apex RAW
Benchmark Scores IT WORKS
In GN testing 50% of the PSU's that Newegg shoved down people's throat with GPU's went kaboom.

It's either bad design, bad components due to component shortages or a mix of both.

The problem that Gigabyte expanded their lineup with CPU coolers, Cases, PSUs, keyboards, headsets mouses, SSDs etc...

Definately all those products are made by OEM partners. Taking price into account they all are not the best choices in the market. In best case scenario they just have bad price performance ratio. In the worst case scenario it happens as it happened with this PSU. Sure Gigabyte chosen MEIC as their PSU OEM manufacturer to cut manufacturing costs. The result is blown PSUs.
 
Joined
Dec 26, 2020
Messages
382 (0.26/day)
System Name Incomplete thing 1.0
Processor Ryzen 2600
Motherboard B450 Aorus Elite
Cooling Gelid Phantom Black
Memory HyperX Fury RGB 3200 CL16 16GB
Video Card(s) Gigabyte 2060 Gaming OC PRO
Storage Dual 1TB 970evo
Display(s) AOC G2U 1440p 144hz, HP e232
Case CM mb511 RGB
Audio Device(s) Reloop ADM-4
Power Supply Sharkoon WPM-600
Mouse G502 Hero
Keyboard Sharkoon SGK3 Blue
Software W10 Pro
Benchmark Scores 2-5% over stock scores
Such a leak would be awesome for the developer community, to better support existing hardware
No more crappy RGB Fusion because all of it's code is fixed and integrated into software as OpenRGB or SignalRGB? Would probably be the most useful thing.
 
Joined
Jul 16, 2014
Messages
8,219 (2.16/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
Such a leak would be awesome for the developer community, to better support existing hardware
Do I detect a bit of "oh this is great haha"?

its funny as hell considering the recently psu blowing up GN video
 
Top