supply-chaintrade-pressNewsThe Broadside1 min read

Analog Devices discloses breach; ExfilSquad claims 570K customer records

The chipmaker's SEC filing describes two incidents but won't address the ransomware group's claims, leaving customers to guess whether their data was taken.


TL;DR

Analog Devices disclosed a June 23 intrusion and data exfiltration in an 8-K filed Wednesday, alongside a second "disparate cybersecurity matter" on July 26. The ransomware group ExfilSquad claims to hold more than 570,000 Analog Devices customer records. The company declined to address the ransomware claims, leaving supply-chain customers (including defense contractors who integrate its signal-processing chips) with no clarity on whether their data was compromised.

Analog Devices' 8-K filing says as little as legally required. The $178 billion chipmaker acknowledges two cybersecurity incidents (a June intrusion with confirmed data exfiltration, and a late-July "disparate" matter) but refuses to connect either to ExfilSquad's claim of 570,000 stolen customer records. Analog Devices' spokesperson didn't address questions about the ransomware group, and the company's assurance that neither incident will have a "material impact" is a financial determination, not a security one.

Analog Devices joins a lengthening list

Semiconductor firms have become a favorite target. Microchip Technology's 2024 Play ransomware attack disrupted operations at facilities serving aerospace and defense customers. Applied Materials was hit in 2023. Trio-Tech International reported a ransomware incident at its Singapore subsidiary this March. Advantest, Foxconn, Nexperia, and Foxsemicon have all disclosed attacks in the past two years. Dragos tracked 119 ransomware gangs targeting industrial organizations in 2025 alone, a nearly 50 percent jump from 2024.

What supply-chain customers can't find out

Analog Devices specializes in data conversion and signal processing chips used across defense, automotive, and industrial applications. For the defense contractors who integrate those components into CMMC-scoped systems, the filing raises a question the company won't answer: were any controlled technical data, specifications, or customer identities among the exfiltrated files? The SEC filing's "no material impact" language addresses shareholders. It doesn't tell the supply chain anything about whether their data is sitting in an ExfilSquad archive, or whether it'll show up on a leak site next week.


Published ·Deep Fathom