TSMC faced a $70 million LockBit ransom after supplier Kinmax was breached

Organization
Taiwan Semiconductor Manufacturing Company (TSMC)
Exploit
Third-Party Data Breach
Industry
Semiconductor Manufacturing

Taiwan Semiconductor Manufacturing Company appeared on the LockBit ransomware group's leak site on June 29, 2023 alongside a demand for $70 million, one of the largest publicly posted ransom figures on record. The listing was attributed to National Hazard Agency, a LockBit affiliate, which set a deadline of August 6 and threatened to publish passwords, login credentials and network entry points.

TSMC said the compromise had not occurred on its own systems. The breached party was Kinmax Technology, a Taiwanese system integrator and IT hardware supplier whose customer list also includes Nvidia, Cisco, Microsoft, HPE, Citrix and VMware. Kinmax said it detected an intrusion into an internal engineering testing environment, used to prepare system installations for customers, on June 29.

Both companies characterized the exposed material as limited. TSMC said the leak concerned information relating to server initial setup and configuration, and that the incident had not affected its business operations or compromised any customer information. Kinmax described the files as system installation preparation supplied to customers as default configurations, apologized for the leak of customer names, and said it had put stronger security measures in place.

TSMC said it immediately terminated data exchange with the supplier and applied its standard security response procedures. Neither company said publicly whether the ransom would be paid, and the threatened data had not been published as of early July 2023. A LockBit-linked persona known as Bassterlord had posted screenshots of the intrusion on June 28 and 29, before the leak site entry appeared.

Sources