The chipmaker said it wasn't directly hacked by LockBit but has been exposed due to an intrusion into Kinmax’s systems. Credit: Shutterstock Taiwan Semiconductor Manufacturing Company (TSMC) has blamed one of its equipment suppliers for the LockBit breach that has exposed the chip-making giant to a $70 million ransom demand. The company has identified the breached third-party supplier as Kinmax Technology, a Taiwan-based system integrator, without divulging the nature of the data compromised. "TSMC has recently been aware that one of our IT hardware suppliers experienced a cybersecurity incident, which led to the leak of information pertinent to server initial setup and configuration," TSMC said. On Thursday, one of the affiliates of the LockBit ransomware gang, National Hazard Agency, shared screenshots of directory listings of stolen TSMC files on its leak website, giving TSMC an August 6 deadline to pay $70 million. Failure of payment would cause the hacker group to leak exfiltrated info, including network login credentials for TSMC's IT network, the post said. TSMC blames third-party breach TSMC claimed that third-party supplier Kinmax, the system integrator that works with leading technology players like Hewlett-Packard, Microsoft, VMware, Cisco, and Fortinet, experienced a system breach that exposed its customers to threats. However, the security breach "has not directly affected TSMC’s business operations, nor did it compromise any TSMC’s customer information," TSMC said. "After the incident, TSMC has immediately terminated its data exchange with this supplier in accordance with the company's security protocols and standard operating procedures." National Hazard Agency, said it is prepared to publish a list of what it calls "points of entry" into TSMC's network and passwords and login information for them. "This breach is a great example of why machine identities are just as important as employee identities," said Lior Yaari, CEO and co-founder of Grip Security. "Data is everywhere and accessed from anywhere by anybody. Companies who are able to secure employee and machine identities will be more secure than those that cannot." Kinmax issues apology, downplays breach Kinmax has issued a letter to its customers regarding an intrusion the supplier discovered within its internal testing environment on June 29, allowing unauthorized access to system installation preparation information. It said the breached information has nothing to do with the actual application of the customer, just the basic setting at the time of shipment. "The leaked content mainly consisted of system installation preparation that the company provided to our customers as default configurations," the Kinmax letter read. "At present, no damage has been caused to the customer and the customer has not been hacked by it." Neither TSMC nor Kinmax has publicly confirmed the claims made by LockBit regarding the unauthorized possession of critical TSMC data. Neither party has revealed whether any or both of them would pay the $70 million demand made. "We would like to express our sincere apologies to the affected customers, as the leaked information contained their names which may have caused some inconvenience," Kinmax said. "The company has thoroughly investigated this incident and implemented enhanced security measures to prevent such incidents from occurring in the future." Related content news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Data Breach Government news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software news SpecterOps to use in-house approximation to test for global attack variations The new offering uses atomic tests and in-house approximation in purple team assessment to test all known techniques of an attack. By Shweta Sharma Sep 28, 2023 3 mins Penetration Testing Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe