Security

Cyber-crime

Dark-web kingpin puts 'stolen' internal AMD databases, source code up for sale

Chip designer really gonna need to channel some Zen right now


Updated AMD's IT team is no doubt going through its logs today after cyber-crooks put up for sale what is claimed to be internal data stolen from the US microprocessor designer.

The supposedly swiped information is being peddled on the recently revived the dark-web BreachForums souk. One or more criminals using the handle IntelBroker are offering, in exchange for cryptocurrency, what's claimed to be customer databases, upcoming product specifications and plans, internal financial figures and source code, firmware and ROMs, staff information – including names, user IDs, and phone numbers – and other sensitive info.

We've asked AMD what its next steps are. “We are aware of a cybercriminal organization claiming to be in possession of stolen AMD data," the Epyc and Ryzen design house told us. "We are working closely with law enforcement officials and a third-party hosting partner to investigate the claim and the significance of the data.”

Intelbroker, a BreachForums moderator, has become notorious in data thievery circles after distributing information said to have been stolen during high-profile intrusions of big-name targets. Last month Europol admitted someone had broken into one of its user groups and exfiltrated files. In April, Home Depot confirmed a third-party slip-up led to staff data being leaked, and that same month the Pentagon said one of its partners had also been hit. Intelbroker put data obtained in all three incidents up for grabs on the dark web.

Of course, there's a big difference between claiming to have high-level information to sell and actually possessing it. And anyone interested in chip design would be out of their mind to look at the purportedly stolen AMD blueprints, so it's really not much use for engineers, though for phishers, fraudsters, unscrupulous investors, and others, it's perhaps valuable.

The clock is ticking for Intelbroker. Police around the world are gunning for BreachForums again and those who use it. With so many high-profile digital burglaries, the scumbag will have a target on their back - particularly since they also claim to have handled data stolen from the US Army Missile Command, and the Green Machine isn't known for forgiving and forgetting. ®

Updated to add on June 20

AMD in a statement to the media has sought to downplay the theft, saying it believes "a limited amount of information related to specifications used to assemble certain AMD products was accessed on a third-party vendor site."

Meanwhile, Intelbroker is now peddling internal data supposedly stolen from Apple, which may or may not be a damp squib.

Send us news
Post a comment

AMD internal data reportedly offered for sale

Second sensitive info theft claimed by the same crims since June

Intel's Software Guard Extensions broken? Don't panic

More of a storm in a teacup

AMD's Victor Peng: AI thirst for power underscores the need for efficient silicon

Moore's Law may be running out of steam, but there are still knobs to turn and levers to pull

Microsoft hosts a security summit but no press, public allowed

CrowdStrike, other vendors, friendly govt reps…but not anyone who would tell you what happened

Security biz Verkada to pay $3M penalty under deal that also enforces infosec upgrade

Allowed access to 150K cameras, some in sensitive spots, but has been done for spamming

Security boom is over, with over a third of CISOs reporting flat or falling budgets

Good news? Security is still getting a growing part of IT budget

AMD won’t patch Sinkclose security bug on older Zen CPUs

Kernel mode not good enough for you? Maybe you'll like SMM of this

Alleged Karakut ransomware scumbag charged in US

Plus: Microsoft issues workaround for dual-boot crashes; ARRL cops to ransom payment, and more

White House thinks it's time to fix the insecure glue of the internet: Yup, BGP

Better late than never

CrowdStrike's meltdown didn't dent its market dominance … yet

Total revenue for Q2 grew 32 percent

Volt Typhoon suspected of exploiting Versa SD-WAN bug since June

The same Beijing-backed cyber spy crew the feds say burrowed into US critical infrastructure

Gamers who find Ryzen 9000s disappointingly slow are testing it wrong, says AMD

Those using Windows 11, version 24H2, should see better speed