Supply chain β›“ Supply Chain

Intel Third-Party Breach (May 2023)

πŸ“… 2023-05-01 🏒 Micro Star International (MSI)
Primary Source β†—

Incident Details

Intel investigating leak of Intel Boot Guard private keys after MSI breach. Intel is investigating the leak of alleged private keys used by the Intel BootGuard security feature, potentially impacting its ability to block the installation of malicious UEFI firmware on MSI devices. Intel is investigating the leak of alleged private keys used by the Intel Boot Guard security feature, potentially impacting its ability to block the installation of malicious UEFI firmware on MSI devices. In March, the Money Message extortion gang attacked computer hardware make MSI, claiming to have stolen 1.5TB of data during the attack, including firmware, source code, and databases. Third-party company: Micro Star International (MSI).

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Micro Star International (MSI)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-05-01 Breach occurred
  2. 2023-05-08 Publicly disclosed