Money Message ransomware gang claimed 1.5TB theft from MSI

Organization
Micro-Star International (MSI)
Exploit
Ransomware
Industry
Computer Hardware

Money Message, a ransomware operation that surfaced in late March 2023, added the Taiwanese hardware manufacturer Micro-Star International to its dark web leak site in early April. MSI produces motherboards, graphics cards, laptops and other PC components.

In messages reviewed by BleepingComputer, the group claimed to have taken about 1.5TB from MSI's network, including CTMS and ERP databases and files containing software source code, private keys and BIOS firmware. It demanded a $4 million ransom and threatened to publish the material within roughly five days. BleepingComputer said it had not been able to verify the claims or confirm the data belonged to MSI.

MSI confirmed an incident on April 7, 2023 in a filing with the Taiwan Stock Exchange. The company said part of its information service systems had been affected by a cyberattack and that it had reported the matter to law enforcement and cybersecurity authorities. It said affected systems had gradually resumed normal operation, that it did not expect significant financial or operational impact, and that it was strengthening the information security controls on its network and infrastructure.

MSI did not say when the intrusion occurred, whether it had communicated with the attackers, or what data had been taken. It advised customers to obtain firmware and BIOS updates only from its official website. Researchers noted at the time that Money Message scaled its demands to the size of the victim, seeking sums as low as $500,000 from other organisations.

Sources