NXP Semiconductors told portal account holders their contact data was exposed
- Organization
- NXP Semiconductors
- Exploit
- Hacking
- Industry
- Semiconductors
NXP Semiconductors, the Dutch chipmaker headquartered in Eindhoven, notified users of its online customer portal in early September 2023 that an unauthorized party had taken basic personal information from a system connected to it.
The company said the incident occurred on July 11, 2023 and that its incident response team identified it on July 14. Notification emails did not go out until early September. NXP did not explain the gap between discovery and notification, and did not say how the attacker obtained access.
Those affected held an NXP.com account, which provides access to technical content and community support rather than to any product, ordering or payment system. The data involved included full names, email and postal addresses, business and mobile telephone numbers, company names, job titles and descriptions, and communication preferences.
A company spokesperson said NXP was contacting all affected NXP.com users "out of an abundance of caution to ensure they are aware" and apologized for the inconvenience. NXP said it had reported the incident to the relevant authorities and told recipients to be alert to phishing, noting that genuine messages from the company would not ask for personal information. It described the notice as largely precautionary and declined to say how many people were affected. The breach reached a wider audience after Troy Hunt, who runs the Have I Been Pwned service, posted a copy of the notification email.