IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

TSMC cyber attack was apparently caused by WannaCry

The attack may have cost the iPhone component manufacturer up to 3% of revenues

The cyber attack on iPhone supplier TSMC was apparently caused by a WannaCry variant, the company has revealed. 

The severity of the attack caused the company to shut down some of its factories while the issue was fixed, which meant some plants were out of action for days. Although the problem has mostly been rectified now, it says it's still expecting shipments to be delayed for some time.

The virus was injected into TSMC's systems when a supplier reportedly installed infected software onto some of its machines, without running an antivirus scan. The infection then spread to other locations within the company's network in Tainan, Hsinchu and Taichung, which caused the majority of its facilities to close down temporarily. It's predicted the outage will result in 3% revenue losses for this year.

"We are surprised and shocked," the company's CEO CC Wei said in a statement. "We have installed tens of thousands of tools before, and this is the first time this happened."

But TSMC is determined to learn from its mistakes and it says it now plans to implement better safeguards against such threats in future, relying on machines and automation rather than humans to protect systems.

"We now realize it is not possible for humans not to make mistakes, so now we are inventing a new mechanism that will go online soon. The mechanism doesn't require human intervention."

06/08/2018: Weekend virus attack may cost iPhone supplier TSMC $255m

A virus that hit chipmaker TSMC over the weekend could cost the Apple iPhone supplier $255 million.

Contract manufacturer Taiwan Semiconductor Manufacturing Co said the security incident started on Friday night, when a new tool's software installation failed, requiring it to be connected to the company's wider network, TSMC said in a statement. That let the virus spread, knocking offline an unspecified portion of TSMC's factories in Taiwan.

"This virus outbreak occurred due to misoperation during the software installation process for a new tool, which caused a virus to spread once the tool was connected to the Company's computer network," the company statement reads.

TSMC added: "The degree of infection varied by fab. TSMC contained the problem and found a solution."

The company said 80% of its production facilities were back online, with full recovery by today, but the limited downtime would cost TSMC 3% of its quarterly revenue, which the FT suggested would amount to 255 million. The company added that any shipments delayed by the outage would be made up in the final quarter of the year normally a busy period for tech hardware sales.

TSMC makes processors for the Apple iPhone but also acts as the contract manufacturer for "fabless" chip designers such as Nvidia and AMD, among many others.

Analysts told Reuters that the impact on TSMC's customers should be limited. KGI Securities predicted delays to the chips for the next iPhone launch but noted that manufacturers normally prepare a surplus anyway, so it shouldn't impact Apple's release cycle.

"Long-term, TSMC's trustworthy image is somewhat tainted but it is hard to quantify the effect now," said Mark Li, an analyst at Sanford C. Bernstein, in a report cited by Reuters. 

TSMC said customers had been notified of the incident and the new delivery schedule, adding that at no time was data at risk. "Data integrity and confidential information was not compromised," the statement said. "TSMC has taken actions to close this security gap and further strengthen security measures."

Featured Resources

Accelerating AI modernisation with data infrastructure

Generate business value from your AI initiatives

Free Download

Recommendations for managing AI risks

Integrate your external AI tool findings into your broader security programs

Free Download

Modernise your legacy databases in the cloud

An introduction to cloud databases

Free Download

Powering through to innovation

IT agility drive digital transformation

Free Download

Recommended

Best free malware removal tools 2022
Security

Best free malware removal tools 2022

22 Jun 2022
A guide to cyber security certification and training
Careers & training

A guide to cyber security certification and training

16 Jun 2022
What is shoulder surfing?
social engineering

What is shoulder surfing?

10 Jun 2022
CIAM buyer’s guide
Whitepaper

CIAM buyer’s guide

6 Jun 2022

Most Popular

FCC commissioner urges Apple and Google to remove TikTok from app stores
data protection

FCC commissioner urges Apple and Google to remove TikTok from app stores

29 Jun 2022
Former Uber security chief to face fraud charges over hack coverup
data breaches

Former Uber security chief to face fraud charges over hack coverup

29 Jun 2022
Internet providers look to ease cost of living crisis with cheaper broadband
broadband

Internet providers look to ease cost of living crisis with cheaper broadband

29 Jun 2022