Massive Databreach hits Intel, confidential documentation about processors leaks away
Yet another setback for Intel, it is confirmed that Intel was hit by a data breach, an extensive one where 20 GB of documentation including chip designs and code has leaked away.
Developer Tillie Kottmann has revealed the existence of the documents and says they came to him through an anonymous source. Most of the information is supposed to be protected intellectual property. The developer was told that the information was stolen from Intel in a breach this year.
"They were given to me by an Anonymous Source who breached them earlier this Year, more details about this will be published soon," Kottmann says.
“Most of the things here have NOT been published ANYWHERE before and are classified as confidential, under NDA or Intel Restricted Secret,” the developer added.
There is a list of things that would be in the 20GB download. Below that are roadmaps, but also Kabylake FDK training videos. Intel confirms to Bleeping Computer that it is internal documentation and suspects that someone from a third party with access to NDA documentation from the Resource And Design Center has downloaded it. This is just an initial release of the materials which contains anything from marketing, roadmaps, sales, chip design and testing as well as software.
We are investigating this situation. The information appears to come from the Intel Resource and Design Center, which hosts information for use by our customers, partners and other external parties who have registered for access. We believe an individual with access downloaded and shared this data.
Intel
The hacker who spoke to Kottmann says he found an Intel server on a CDN without proper security through a scan. With a Python script, the hacker would have looked at files and folders that do not require a password or that work with default passwords. It is also suggested that software contains backdoors, which would now get exposed. This initial release contains documents related to the following:
- Intel ME Bringup guides + (flash) tooling + samples for various platforms
- Kabylake (Purley Platform) BIOS Reference Code and Sample Code + Initialization code (some of it as exported git repos with full history)
- Intel CEFDK (Consumer Electronics Firmware Development Kit (Bootloader stuff)) SOURCES
- Silicon / FSP source code packages for various platforms
- Various Intel Development and Debugging Tools
- Simics Simulation for Rocket Lake S and potentially other platforms
- Various roadmaps and other documents
- Binaries for Camera drivers Intel made for SpaceX
- Schematics, Docs, Tools + Firmware for the unreleased Tiger Lake platform
- (very horrible) Kabylake FDK training videos
- Intel Trace Hub + decoder files for various Intel ME versions
- Elkhart Lake Silicon Reference and Platform Sample Code
- Some Verilog stuff for various Xeon Platforms, unsure what it is exactly
- Debug BIOS/TXE builds for various Platforms
- Bootguard SDK (encrypted zip)
- Intel Snowridge / Snowfish Process Simulator ADK
- Various schematics
- Intel Marketing Material Templates (InDesign)
This release has already been dubbed “juicy” but Kottmann believes that future leaks from their source are likely to contain even “juicier” classified documents.
Gigabyte Aorus Threadripper 3000 motherboard reveals active cooling and massive VRM - 10/21/2019 09:09 AM
Gigabyte has decided to jump embargo one again by silently leaking a darkened photo of their new Threadripper board, which you can easily brighten up with Photoshop of course. It's one of the many ti...
Intel Procs Again hit By Massive Vulnerability (called Spoiler) - 03/05/2019 04:17 PM
Yeah, not exactly the most fun pun, but this is a spoiler alert. The vulnerability was given the name Spoiler and was discovered by the Worcester Polytechnic Institute and the University of Lübeck. ...
Star Citizen developer says ray tracing "a massive headache" - 02/19/2019 09:26 AM
Over on the Star Citizen forums, a player of the space sim asked, "Do you, as I, believe that RTX tech will save you devs so much work farther along and look absolutely spanking?"...
G.SKILL Announces New Hexa-Channel Massive Capacity DDR4 Memory Kits - 01/30/2019 07:19 PM
G.SKILL is delighted to announce the latest 6-channel Trident Z Royal memory specifications, up to 192GB (16GBx12) DDR4-4000 CL17-18-18-38 , geared towards the latest 28-core Intel Xeon W-3175X proce...
Valve Patched Massive Vulnerability in Steam (that was there for 10+ years) - 06/01/2018 09:10 AM
Let me first jump into Valve's defense, they didn't know about this vulnerability, got the report, and plugged the security hole in less than eight hours. However, the vulnerability (and it was a ba...
Senior Member
Posts: 1220
Joined: 2010-05-12
Well, I got bad news for you. People will do whatever they want, be it to get money by selling documents or blackmailing Intel or just for fun.
That why you don't skip your security classes and pay attention when handling sensitive information.
I know that stupid people exists, just for fun or 2 days of glory.
I would have asked a fair normal compensation for not doing any harm, and a public statement from intel that a security breach has been discovered, reported and fixed.
A normal world, sadly people are what they are.
Senior Member
Posts: 11339
Joined: 2004-05-10
If the hacker was able to breach Intel so easily, I'll bet the Chinese already have all this data even before him.
Senior Member
Posts: 7989
Joined: 2010-08-28
I'm ready for my 4770K to be downgraded further into a Pentium 1.
Senior Member
Posts: 108
Joined: 2019-06-08
Guess Intel will be doing that thorough security audit they should have been doing more often. Guess they have to learn the hard way. Going to be interesting reading when it hits the public realm.
Posts: 6073
Joined: 2011-01-02
Release the kraken!
What kraken? I only see AMD fanboys jeez all over the place