Supermicro finds no evidence of China spy chip infiltration

An investigation of the firm’s products finds no evidence of tampering as its CEO hits back at the initial reports

Image of a motherboard being examined closely

Hardware manufacturer Supermicro has released the findings of an audit showing no evidence that malicious chips have been inserted into its widely-used motherboards.

Concerns were sparked after a Bloomberg report in October alleged Chinese operatives had been conducting covert surveillance on major firms such as Apple and Amazon by inserting spy chips' onto Supermicro's motherboards.

Advertisement - Article continues below

But the firm has now shared the results of a "thorough investigation" of its hardware conducted via a third-party investigations firm and has concluded its chips have not been infiltrated by any threat actors.

"After thorough examination and a range of functional tests, the investigations firm found absolutely no evidence of malicious hardware on our motherboards," Supermicro's president and CEO Charles Liang said in a letter to customers.

"These findings were no surprise to us. As we have stated repeatedly, our process is designed to protect the integrity and reliability of our products."

After the allegations first emerged, both the US Department for Homeland Security (DHS) and the UK's National Cyber Security Centre (NCSC) backed up Supermicro's statements, each suggesting there were no reasons to doubt the denials.

But the statements came after no official investigation had taken place, with the findings of the newly published security audit, conducted by a third-party company, the only examination of Supermicro's hardware since the reports emerged.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"As we have stated repeatedly since these allegations were reported, no government agency has ever informed us that it has found malicious hardware on our products," Laing continued.

"No customer has ever informed us that it found malicious hardware on our products, and we have never seen any evidence of malicious hardware on our products.

"Today's announcement should lay to rest the unwarranted accusations made about Supermicro's motherboards. We know that many of you are also addressing these issues with your own customers."

The investigations firm tested a representative sample of Supermicro's motherboards, including the specific motherboard Bloomerberg referenced in its initial report, motherboards bought by companies referenced in the article, and more recently manufactured hardware.

Supermicro has also said there is a range of safeguards in place to ensure it's difficult as possible to release motherboards that have been tampered with or infiltrated by threat actors, Chinese or otherwise.

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/security/28170/what-is-cyber-warfare
Security

What is cyber warfare?

16 Mar 2020
Visit/security/ransomware/355909/microsoft-issues-warning-about-new-ponyfinal-ransomware-attacks
ransomware

Microsoft issues warning about new PonyFinal ransomware attacks

3 Jun 2020
Visit/security/data-breaches/355908/amtrak-guest-reward-suffers-a-data-breach
data breaches

Amtrak Guest Reward suffers a data breach

3 Jun 2020
Visit/security/cyber-security/355903/brand-impersonation-and-form-based-attacks-are-rising
cyber security

Brand-impersonation and form-based attacks are rising

3 Jun 2020

Most Popular

Visit/security/ransomware/355891/nasa-it-contractor-ransomware-hack
ransomware

Ransomware collective claims to have hacked NASA IT contractor

3 Jun 2020
Visit/security/exploits/355866/critical-vmware-cloud-director-exploit-lets-hackers-seize-corporate
exploits

VMware Cloud Director exploit lets hackers seize corporate servers

2 Jun 2020
Visit/data-insights/data-science/355678/how-data-science-is-transforming-business
Sponsored

How data science is transforming business

29 May 2020