• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

AMD Investigates Claims of a Data Breach by a Hacking Group

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
46,728 (7.65/day)
Location
Hyderabad, India
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard ASUS ROG Strix B450-E Gaming
Cooling DeepCool Gammax L240 V2
Memory 2x 8GB G.Skill Sniper X
Video Card(s) Palit GeForce RTX 2080 SUPER GameRock
Storage Western Digital Black NVMe 512GB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
AMD has reportedly suffered a cybersecurity breach, with an organization that goes by "IntelBroker" claiming to have stolen company data on future products, customer databases, and financial records, among others. In a statement to Reuters, AMD said that it is working closely with law enforcement agencies and a third-party hosting partner, to investigate the claim of a data breach by IntelBroker. "We are working closely with law enforcement officials and a third-party hosting partner to investigate the claim and the significance of the data," the company said. The AMD stock traded slightly down (by 2.38% as of this writing) on Tuesday.

HackRead goes into the details of the data IntelBroker claims to have stolen. There are broadly two categories of data in the breach—IP and product information; and business information. In terms of IP, IntelBroker claims to have done away with files related to device firmware, ROMs, source code, IP files, future AMD product plans, and technical specifications. The business information leaked includes employee databases, customer databases, financial information, user IDs (probably of employees), job designation, employment statuses, and business phone numbers.



In most such data breaches of major corporations, the hacking group demands a ransom to be paid, failing when it threatens to release the sensitive and confidential information to public. IntelBroker, however, has a different modus operandi—they have begun selling the information to interested parties, and accept cryptocurrency through a middleman as payment. IntelBroker has a long list of exploits, including HSBC, Barclays, T-Mobile, Los Angeles International Airport, Europol, Home Depot, Acuity Inc., and Facebook Marketplace.

View at TechPowerUp Main Site | Source
 
Joined
Oct 18, 2013
Messages
5,727 (1.47/day)
Location
In the abyss, where all I can see is...nuthin !
System Name The Little One
Processor i5-11320H @4.4GHZ
Motherboard AZW SEI
Cooling Fan w/heat pipes + side & rear vents
Memory 64GB Crucial DDR4-3200 (2x 32GB)
Video Card(s) Iris XE
Storage WD Black SN850X 4TB m.2, Seagate 2TB SSD + SN850 4TB x2 in an external enclosure
Display(s) 2x Samsung 43" & 2x 32"
Case Practically identical to a mac mini, just purrtier in slate blue, & with 3x usb ports on the front !
Audio Device(s) Yamaha ATS-1060 Bluetooth Soundbar & Subwoofer
Power Supply 65w brick
Mouse Logitech MX Master 2
Keyboard Logitech G613 mechanical wireless
Software Windows 10 pro 64 bit, with all the unnecessary background shitzu turned OFF !
Benchmark Scores PDQ
Why ??

Do these mega corps, especially those in the computing business, who should have millions of $$ dedicated to/invested in data security devices, practices and systems, continue to suffer breaches....

And, "the significance of the data".... seriously, like WTF ?.......

Any leaked data is significant, and normally, whatever amount of data you think they got, they probably got a buttload more that you just don't know about.. yet, as most of it has already been sold/distributed on the dark web...

OR...

This is just a smoke screen/excuse for lining up a bunch of dud/under-performing/unwanted employees for the unemployment lines, those who haven't really done anything wrong, but have not contributed anything of significance to the company and therefore fall into the grey area of "lets find a way to replace a bunch of seasoned/tenured folks with dweebs, tweenie-bots and ewwtooberz and pay them 1/2 as much money for the same work"
 
Joined
Sep 17, 2014
Messages
21,445 (6.01/day)
Location
The Washing Machine
Processor i7 8700k 4.6Ghz @ 1.24V
Motherboard AsRock Fatal1ty K6 Z370
Cooling beQuiet! Dark Rock Pro 3
Memory 16GB Corsair Vengeance LPX 3200/C16
Video Card(s) ASRock RX7900XT Phantom Gaming
Storage Samsung 850 EVO 1TB + Samsung 830 256GB + Crucial BX100 250GB + Toshiba 1TB HDD
Display(s) Gigabyte G34QWC (3440x1440)
Case Fractal Design Define R5
Audio Device(s) Harman Kardon AVR137 + 2.1
Power Supply EVGA Supernova G2 750W
Mouse XTRFY M42
Keyboard Lenovo Thinkpad Trackpoint II
Software W10 x64
EAU NEAU

a data breach. How is this news :D There are like thousands of them daily, and China already has AMDs IP by now right?
 
Joined
Jan 2, 2024
Messages
279 (1.58/day)
Location
Seattle
System Name DevKit
Processor AMD Ryzen 5 3600 ↗4.0GHz
Motherboard Asus TUF Gaming X570-Plus WiFi
Cooling Koolance CPU-300-H06, Koolance GPU-180-L06, SC800 Pump
Memory 4x16GB Ballistix 3200MT/s ↗3600
Video Card(s) PowerColor RX 580 Red Devil 8GB ↗1380MHz ↘1105mV, PowerColor RX 7900 XT Hellhound 20GB
Storage 240GB Corsair MP510, 120GB KingDian S280
Display(s) Nixeus VUE-24 (1080p144)
Case Koolance PC2-601BLW + Koolance EHX1020CUV Radiator Kit
Audio Device(s) Oculus CV-1
Power Supply Antec Earthwatts EA-750 Semi-Modular
Mouse Easterntimes Tech X-08, Zelotes C-12
Keyboard Logitech 106-key, Romoral 15-Key Macro, Royal Kludge RK84
VR HMD Oculus CV-1
Software Windows 10 Pro Workstation, VMware Workstation 16 Pro, MS SQL Server 2016, Fan Control v120, Blender
Benchmark Scores Cinebench R15: 1590cb Cinebench R20: 3530cb (7.83x451cb) CPU-Z 17.01.64: 481.2/3896.8 VRMark: 8009
Dude it's been a while but last I checked China was still restricted to Ryzen 2nd gen stuff.
Any of that data making it over The Great Firewall™ is kind of a big deal so I'd keep an eye out for it.
Also, IntelBroker.....LUL. That's a bit on the nose.
 
Joined
Apr 13, 2023
Messages
247 (0.56/day)
System Name Can it run Warhammer 3?
Processor 7800X3D @ 5Ghz
Motherboard Gigabyte B650 Aorus Elite AX
Cooling Enermax Liqmax III 360mm
Memory Corsair Vengeance @ 6000Mhz
Video Card(s) Asus Strix 3080
Storage Silicon Power XS70
Display(s) BenQ EX2710Q, BenQEX270M
Case NZXT H7 Flow
Audio Device(s) AudioTechnica M50xBT
Power Supply SuperFlower Leadex III 850W
Why ??

Do these mega corps, especially those in the computing business, who should have millions of $$ dedicated to/invested in data security devices, practices and systems, continue to suffer breaches....

And, "the significance of the data".... seriously, like WTF ?.......

Any leaked data is significant, and normally, whatever amount of data you think they got, they probably got a buttload more that you just don't know about.. yet, as most of it has already been sold/distributed on the dark web...
Because cybersecurity practices can only diminish the risk of a breach to a certain point.
 
Joined
May 11, 2018
Messages
1,023 (0.46/day)
Why ??

Do these mega corps, especially those in the computing business, who should have millions of $$ dedicated to/invested in data security devices, practices and systems, continue to suffer breaches....

With tons of previous breaches, some even unrelated to AMD, hackers can easily use personal information of employees for a very personal phishing. And with this new leak of employee information the vicious circle will continue, some other group will use this information to gain access to AMD and their partners...
 
Joined
Oct 6, 2021
Messages
1,592 (1.60/day)
Nothing to with Intel, huh :nutkick:
"Intelbroker" indeed sounds comical. I always suspected that Intel was trying to get AMD's secrets, but I never imagined their desperation would go this far. /s

I'm not sure if they'll still find it funny when they end up caught and thrown into a dark cell tbh.
 
Joined
Feb 13, 2023
Messages
55 (0.11/day)
Location
Hell
I'm glad they finally released a statement...like a week after the group claimed to have breached them and only after they actually put stuff up for sale.
 
Joined
Jul 7, 2019
Messages
873 (0.48/day)
Kind of surprised they haven't gone after NVIDIA or Intel; both seem like juicier targets considering one has a virtual monopoly in the accelerator/GPU space and the other still has a good lead when it comes to a lot of used computer CPUs, especially in Europe and Asia.
 
Joined
Oct 3, 2015
Messages
30 (0.01/day)
System Name "The Killer"
Processor i9-14900KS
Motherboard ASUS ROG Max Z790 Apex Encore
Cooling Custom Cooling
Memory G. Skill - 32GB DDR5
Video Card(s) 4090 HOF + 20 other graphics cards
Storage Samsung 990 Pro
Display(s) Asus ROG Strix XG27AQ 27" Monitors
Case Corsair Obsidian 1000D
Audio Device(s) On Board
Power Supply Be Quiet! Dark Power Pro 12 - 1500 Watt. Second PSU - Cooler Master V750 SFX Gold 750W (For total o
Mouse Logitech G900
Keyboard Corsair K95
Software Div
Well, if you can't beat them, just steal their IP. :eek:
Or put it the other way...

How can you make secure hardware when you can't secure your own network? Maybe AMD used own hardware? Or just their own home brewed software? Clearly they struggle with the improvements. Maybe it's on time ask professionals for help and not try fix it themself? Because they seems to come short on this :)

This is not AMD's first encounter with cybersecurity challenges. In 2022, the company was targeted by the RansomHouse hacking group, which also claimed to have extracted data from AMD's networks. That incident led to an extensive investigation by AMD to assess the damage and bolster its security measures.

This isn't the first time a group has claimed to have breached AMD's systems. In 2022, ransomware gang RansomHouse said it stole 450GB of data from Team Red. AMD launched an investigation into the claims and improved its security measures as a result, though it appears the changes weren't enough to prevent another incident.
 
Joined
Apr 13, 2023
Messages
247 (0.56/day)
System Name Can it run Warhammer 3?
Processor 7800X3D @ 5Ghz
Motherboard Gigabyte B650 Aorus Elite AX
Cooling Enermax Liqmax III 360mm
Memory Corsair Vengeance @ 6000Mhz
Video Card(s) Asus Strix 3080
Storage Silicon Power XS70
Display(s) BenQ EX2710Q, BenQEX270M
Case NZXT H7 Flow
Audio Device(s) AudioTechnica M50xBT
Power Supply SuperFlower Leadex III 850W
Or put it the other way...

How can you make secure hardware when you can't secure your own network?
The security of a network hinges on the people using it more often than the network itself. Hardware lacks the people component.

When people see these cyber attacks they think of someone furiously typing away "hacking" an actual network, but more often than not the attack is done through phishing and/or social engineering by email.
 
Joined
Oct 22, 2014
Messages
13,407 (3.79/day)
Location
Sunshine Coast
System Name Lenovo ThinkCentre
Processor AMD 5650GE
Motherboard Lenovo
Memory 32 GB DDR4
Display(s) AOC 24" Freesync 1m.s. 75Hz
Mouse Lenovo
Keyboard Lenovo
Software W11 Pro 64 bit
Or put it the other way...

How can you make secure hardware when you can't secure your own network? Maybe AMD used own hardware? Or just their own home brewed software? Clearly they struggle with the improvements. Maybe it's on time ask professionals for help and not try fix it themself? Because they seems to come short on this :)

This is not AMD's first encounter with cybersecurity challenges. In 2022, the company was targeted by the RansomHouse hacking group, which also claimed to have extracted data from AMD's networks. That incident led to an extensive investigation by AMD to assess the damage and bolster its security measures.

This isn't the first time a group has claimed to have breached AMD's systems. In 2022, ransomware gang RansomHouse said it stole 450GB of data from Team Red. AMD launched an investigation into the claims and improved its security measures as a result, though it appears the changes weren't enough to prevent another incident.
The article implies AMD itself wasn't hacked, so I'm sure their policies are rigorous enough.
"AMD said that it is working closely with law enforcement agencies and a third-party hosting partner"
 
Joined
Sep 19, 2023
Messages
14 (0.05/day)
System Name IdeaPad Gaming 3 15ARH7
Processor Ryzen 5 6600H
Memory 16GB DDR5 4800MHz CL34
Video Card(s) RTX 3050 4GB Laptop
Storage Samsung 980 Pro 1TB
Audio Device(s) Moondrop Quarks 3.5mm
Mouse Logitech G304
wow, what did i just see?
AMD ABOUT TO RELEASE MORE AM4 CPU?
 
Joined
Oct 27, 2009
Messages
1,148 (0.21/day)
Location
Republic of Texas
System Name [H]arbringer
Processor 4x 61XX ES @3.5Ghz (48cores)
Motherboard SM GL
Cooling 3x xspc rx360, rx240, 4x DT G34 snipers, D5 pump.
Memory 16x gskill DDR3 1600 cas6 2gb
Video Card(s) blah bigadv folder no gfx needed
Storage 32GB Sammy SSD
Display(s) headless
Case Xigmatek Elysium (whats left of it)
Audio Device(s) yawn
Power Supply Antec 1200w HCP
Software Ubuntu 10.10
Benchmark Scores http://valid.canardpc.com/show_oc.php?id=1780855 http://www.hwbot.org/submission/2158678 http://ww
Why ??

Do these mega corps, especially those in the computing business, who should have millions of $$ dedicated to/invested in data security devices, practices and systems, continue to suffer breaches....
You are only as strong as your dumbest employee.
On average it only takes $75 to get the password from someone at a bar. (fbi number)
They assume they can just pocket the money and go change their password but the attackers typically have already gained the rest of the credentials...
Social engineering... its easier than brute force.
 
Top