Analog Devices discloses data exfiltration and separate ransomware claim
Analog Devices disclosed a June intrusion involving file exfiltration and a separate matter reported on 26 July. The company expects no material impact and said the data had not been publicly released or used fraudulently; ExfilSquad's claim of stealing more than 570,000 records remains unverified.
Affected
Analog Devices identified unauthorised access to certain systems on 23 June and later found that files had been exfiltrated. The semiconductor manufacturer engaged external specialists, coordinated with law enforcement and reported the incident to the US Securities and Exchange Commission (SEC).
The company said it did not expect the intrusion to have a material impact on its business. To its knowledge, the affected data had not been publicly released or used for fraudulent purposes. The scope remained under investigation at disclosure.
Analog Devices was also informed of a second, separate cybersecurity matter on 26 July and was assessing its validity, scope and potential impact. The ransomware group ExfilSquad claimed to have stolen more than 570,000 customer-related records, but this is an unverified ransomware claim and Analog Devices did not confirm a connection.
The intrusion method has not been disclosed. Any discussion of an initial-access vector, lateral movement or supply-chain path is therefore inference rather than a confirmed finding. Downstream organisations should base any response on verified notifications and technical indicators from Analog Devices.
The unresolved scope prevents a detailed exposure assessment, but the company's no-material-impact statement and the absence of known release or fraudulent use should remain central to the current risk judgement.
Sources