Acer confirms breach of repair technician document server
- Organization
- Acer
- Exploit
- Hacking
- Industry
- Technology Manufacturing
Acer confirmed in March 2023 that one of its document servers had been accessed without authorisation in mid-February. The company said the server was used by repair technicians and that its investigation had found no indication that any consumer data was stored on it.
The confirmation followed a listing on the BreachForums hacking forum, where a seller using the alias Kernelware offered what they described as 160 GB of Acer data comprising 655 directories and 2,869 files. The seller said they would sell the whole set to a single buyer and would accept only the privacy coin Monero.
The advertised material was technical rather than personal. According to the listing, it included confidential slides and presentations, staff technical manuals, Windows Imaging Format files, binaries, backend infrastructure data, product documentation for phones, tablets and laptops, replacement digital product keys, ISO files, Windows system deployment images, BIOS components and ROM files.
Acer did not say how the server was reached or whether it had verified the seller's claims, and described its investigation as ongoing. The incident followed two earlier security events at the company in 2021: a REvil ransomware attack carrying a $50 million demand, and a separate intrusion claimed by the Desorden group.