LockBit defaces Foxsemicon website and claims 5TB of stolen data

Organization
Foxsemicon Integrated Technology
Exploit
Ransomware
Industry
Semiconductor Manufacturing

Foxsemicon Integrated Technology, a Taiwanese semiconductor equipment maker in the Foxconn group, found its public website replaced on January 17, 2024 with a ransom message from the LockBit ransomware operation.

The message claimed the attackers held five terabytes of company data, including personal information belonging to Foxsemicon customers and employees, and threatened to publish it on LockBit's darknet leak site unless the company paid. LockBit warned that once the data appeared there, competitors could buy it. As proof the group circulated a small set of documents, among them payment card details, a bank account balance, internal account records and scans of two employee passports.

Foxsemicon told the Taiwan Stock Exchange that it had restored the website shortly after detecting the attack and had brought in outside security specialists. Its initial assessment was that the incident should not significantly affect operations. The company did not disclose the ransom demanded and did not confirm whether any customer or employee data had actually been taken. Its shares fell about 3 percent that day, and parts of the site remained unreachable for a period afterwards.

Defacing a victim's website was an unusual tactic for LockBit, which normally lists victims on its leak site instead. Foxsemicon had not appeared on that site at the time of the first reports, and SecurityWeek noted that it is not uncommon for ransomware gangs to exaggerate their claims in order to put more pressure on the victim.

Sources