Gigabyte Suffered Ransomware Attack, And 112GB Worth Of Data Has Been Stolen

Gigabyte is a Taiwanese manufacturer and distributor of computer hardware, known as one of the leading motherboard vendor.

The company is also a manufacturer of custom graphic cards, as well as laptop computers, data center servers and monitors.

This time, the publicly-traded company has been hit by ransomware attack.

The attack occurred on August 3rd and August 4th, and forced the company to shut down its entire systems in Taiwan.

The incident also affected a number of its websites, including its support website and portions of its Taiwanese website.

Customers have also reported issues accessing support documents, and experiencing issues when receiving updated information about RMAs, which is likely due to the ransomware attack.

The non-public Gigabyte data leak page
The non-public Gigabyte data leak page. (Credit: Bleeping Computer)

Gigabyte later confirmed that it suffered a cyberattack that affected a small number of servers.

It started when it detected abnormal activity on its network.

After shutting down its IT system operations, Gigabyte notified the law enforcements.

It is later known that the attack was conducted by the RansomEXX gang, which encrypted its network, and created ransom notes for each encrypted device.

These ransom notes contain a link to a non-public page that is meant to be accessed only by Gigabyte, so the company can test the decryption of one of the affected file, and to also leave an email address for the two parties to begin ransom negotiations.

During the attack, the threat actors claimed to have stolen 112GB of data from an internal Gigabyte network as well as the American Megatrends Git Repository, many of which are under non-disclosure agreements (NDA) with companies like Intel, AMD and also American Megatrends.

The ransomware gang threatens Gigabyte, saying that it would leak the data if the ransom is not paid.

[block:block=87]

The RansomEXX ransomware gang originally started its operations under the name Defray in 2018.

It changed its name to RansomEXX in June 2020, when its operations become more active, and have targeted high-profile entities, like the Brazilian government, Texas' Department of Transportation and more.

Just like other ransomware gangs, RansomEXX breaches vulnerable systems using Remote Desktop Protocol, to then exploits the affected systems. to then steal credentials and other sensitive information.

Once the hackers gain privilege to the network, they will continue to harvest even more data, and also more credentials.

RansomEXX is known to mostly target Windows systems.

It's not surprising for hackers to attack tech and PC companies like Gigabyte, knowing that most of its operations have been digitized, and it has technological secrets it needs to protect.

Previously, RansomEXX gang has also attacked Italy's Lazio region, as well as Ecuador's state-run Corporación Nacional de Telecomunicación (CNT).