Gigabyte confirmed it contacted law enforcement after it shut down IT infrastructure following a handful of servers in Taiwan being affected.
Extortion gang RansomEXX claimed to have stolen 112GB of sensitive internal data and other information from a code repository. This includes Intel and AMD chip information as well as a debug document. The breach is known to have affected both the Gigabyte support page and parts of the Taiwanese page, according to Bleeping Computer sources.
RansomEXX started in 2018 under the Defray name, but rebranded in 2020. The threat actor has been targeting increasingly high-profile organisations, including the Brazilian government, Texas' Department of Transportation and Ecuador's state-led telecom. It's not believed to be associated with the REvil group that attacked Acer as well as Apple supplier Quanta.
Gigabyte did not comment on whether it would pay the ransom.
[Related: ACSC issues LockBit 2.0 ransomware alert]
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.