TSMC cyber attack was apparently caused by WannaCry

The attack may have cost the iPhone component manufacturer up to 3% of revenues

The cyber attack on iPhone supplier TSMC was apparently caused by a WannaCry variant, the company has revealed. 

The severity of the attack caused the company to shut down some of its factories while the issue was fixed, which meant some plants were out of action for days. Although the problem has mostly been rectified now, it says it's still expecting shipments to be delayed for some time.

The virus was injected into TSMC's systems when a supplier reportedly installed infected software onto some of its machines, without running an antivirus scan. The infection then spread to other locations within the company's network in Tainan, Hsinchu and Taichung, which caused the majority of its facilities to close down temporarily. It's predicted the outage will result in 3% revenue losses for this year.

"We are surprised and shocked," the company's CEO CC Wei said in a statement. "We have installed tens of thousands of tools before, and this is the first time this happened."

Advertisement
Advertisement - Article continues below

But TSMC is determined to learn from its mistakes and it says it now plans to implement better safeguards against such threats in future, relying on machines and automation rather than humans to protect systems.

"We now realize it is not possible for humans not to make mistakes, so now we are inventing a new mechanism that will go online soon. The mechanism doesn't require human intervention."

06/08/2018: Weekend virus attack may cost iPhone supplier TSMC $255m

A virus that hit chipmaker TSMC over the weekend could cost the Apple iPhone supplier $255 million.

Contract manufacturer Taiwan Semiconductor Manufacturing Co said the security incident started on Friday night, when a new tool's software installation failed, requiring it to be connected to the company's wider network, TSMC said in a statement. That let the virus spread, knocking offline an unspecified portion of TSMC's factories in Taiwan.

"This virus outbreak occurred due to misoperation during the software installation process for a new tool, which caused a virus to spread once the tool was connected to the Company's computer network," the company statement reads.

TSMC added: "The degree of infection varied by fab. TSMC contained the problem and found a solution."

The company said 80% of its production facilities were back online, with full recovery by today, but the limited downtime would cost TSMC 3% of its quarterly revenue, which the FT suggested would amount to 255 million. The company added that any shipments delayed by the outage would be made up in the final quarter of the year normally a busy period for tech hardware sales.

TSMC makes processors for the Apple iPhone but also acts as the contract manufacturer for "fabless" chip designers such as Nvidia and AMD, among many others.

Analysts told Reuters that the impact on TSMC's customers should be limited. KGI Securities predicted delays to the chips for the next iPhone launch but noted that manufacturers normally prepare a surplus anyway, so it shouldn't impact Apple's release cycle.

Advertisement
Advertisement - Article continues below

"Long-term, TSMC's trustworthy image is somewhat tainted but it is hard to quantify the effect now," said Mark Li, an analyst at Sanford C. Bernstein, in a report cited by Reuters. 

TSMC said customers had been notified of the incident and the new delivery schedule, adding that at no time was data at risk. "Data integrity and confidential information was not compromised," the statement said. "TSMC has taken actions to close this security gap and further strengthen security measures."

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/business/business-strategy/354195/where-modernisation-and-sustainability-meet-a-tale-of-two
Sponsored

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019