News: 1634705108

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Acer servers cracked in India and Taiwan – including systems with customer data

(2021/10/20)


Taiwanese PC maker Acer has not only admitted servers it operates in India and and Taiwan were compromised but that only those systems in India contained customer data.

The miscreants who claimed to be behind the network breaches boasted they stole gigabytes of information from the servers, and suggested other Acer operations around the world are also vulnerable to information theft.

Acer issued the following statement this week about the affair:

We have recently detected an isolated attack on our local after-sales service system in India and a further attack in Taiwan. Upon detection, we immediately initiated our security protocols and conducted a full scan of our systems. We are notifying all potentially affected customers in India, while the attacked Taiwan system does not involve customer data. The incident has been reported to local law enforcement and relevant authorities, and has no material impact to our operations and business continuity.

An entity that calls itself Desorden Group – Desorden is Spanish for disorder – claimed it conducted both attacks. In posts to the notorious [1]RAIDforums , the crew said it swiped 60GB from Acer India, which included "customer, corporate, accounts, and financial data." The gang also leaked login details that retailers and distributors in India use to access Acer systems as well as some customer records to support its boasts.

In a video seemingly revealing some of this stolen data, Desorden also stated it has over 900,000 database records describing individual Acer customers plus "corporate, financial, [and] audit" data. The video, viewed by The Register , shows rows of a spreadsheet that list addresses in Malaysia as well as India.

[2]

Desorden also [3]claimed responsibility for the attack on Acer Taiwan, alleging it accessed product information and employee data.

[4]Acer expands its antimicrobial PC offerings – with caveat they may not offer any protection

[5]Is that a meteor crashing to Earth? No, it's Chromebook makers coming back to reality

[6]REvil ransomware gang claims it stole top-secret tech designs – including Apple lappies – from Quanta Computer

The post claiming responsibility for the Taiwan attack also revealed Desorden's motives.

"To prove our point that Acer is a global network of vulnerable servers, we have hacked and breached Acer Taiwan," the post stated. "We did not steal all data, and only took data pertaining to their employee details. Right after the breach, we informed Acer management on the Taiwan server breach and Acer has since taken the affected server offline."

[7]

The crew said "a few other" Acer outposts are also vulnerable, and named Malaysia and Indonesia as those at risk.

The security breaches follow a March 2021 incident that saw Acer fall victim to the REvil ransomware.

[8]

Desorden appears to be trying to make the point that Acer needs to harden up, and that shaming it into doing so with repeated attacks has become necessary. ®

Get our [9]Tech Resources



[1] https://rfmirror.com/Thread-ACER-HACKED-BREACHED-BY-DESORDEN

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YXA9QkjoBJr5kK5vAX5hyQAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://rfmirror.com/Thread-FRESH-LEAK-Acer-Taiwan-Server-Breached-By-Desorden?pid=4492816#pid4492816

[4] https://www.theregister.com/2021/10/14/acer_antimicrobial_cps/

[5] https://www.theregister.com/2021/10/13/chroembook_sales_crash/

[6] https://www.theregister.com/2021/04/21/ransomware_gang_extorts_apple/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXA9QkjoBJr5kK5vAX5hyQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXA9QkjoBJr5kK5vAX5hyQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/



Message not getting through

sanmigueelbeer

and that shaming it into doing so with repeated attacks has become necessary is not working

TFTFY

Do not allow this language (Ada) in its present state to be used in
applications where reliability is critical, i.e., nuclear power stations,
cruise missiles, early warning systems, anti-ballistic missile defense
systems. The next rocket to go astray as a result of a programming language
error may not be an exploratory space rocket on a harmless trip to Venus:
It may be a nuclear warhead exploding over one of our cities. An unreliable
programming language generating unreliable programs constitutes a far
greater risk to our environment and to our society than unsafe cars, toxic
pesticides, or accidents at nuclear power stations.
-- C. A. R. Hoare