Sources: Supermicro firmware portal was breached in 2015 and some customers downloaded malware; Facebook was among them, says no servers were used in production
This week Bloomberg Businessweek (BBW) … Evgeny Morozov / The Guardian : Reasserting cyber sovereignty: how states are taking back control Alan Patterson / EE Times : Analysts Foresee Supply Chain Impact from Chip Hack Report Wayne Rash / eWeek : A Chip Off the Old Computer Ryan Faas / Computerworld : Spy chips on servers? Lessons learned (and questions to ask) Washington Post : China is secretly hacking computer motherboards. The economic fallout is huge. Philip Ewing / NPR : The Russia Investigations: The New Era Of Foreign Threats Marisa Fernandez / Axios : Tech news you might have missed this week Brian Krebs / Krebs on Security : Supply Chain Security is the Whole Enchilada, But Who's Willing to Pay for It? Kieren McCarthy / The Register : Decoding the Chinese Super Micro super spy-chip super-scandal: What do we know - and who is telling the truth? Sergiu Gatlan / Softpedia News : Supermicro also Had Their Update Portal Hacked in 2015 Rachel Kraus / Mashable : Facebook, Apple confirm they were targets of Supermicro malware attack Susan Bradley / AskWoody : Patch Lady - 31 days of paranoia - day 5 Varada Bhat / Business Insider : Hedge fund billionaire David Einhorn reportedly dumps his Apple stock on trade fears Peter Cao / 9to5Mac : Apple's retired legal chief further confirms Apple has ‘never heard of’ these Chinese server spies Tweets: Troels Oerting / @troelsoerting : There has been a lot of ‘fog of war’ regarding the alleged implantation of Trojan hardware into Supermicro servers at manufacturing time. Other analyses have cast doubt on the story. But do all the pieces pass the sniff test? Read more here. http://www.lightbluetouchpaper.org/ ... Iang / @iang_fc : Bloomberg doubles down with yet another article attacking Supermicro http://www.bloomberg.com/... Denials from all. At this stage, ONLY source is anonymous unconfirmable intelligence reports. Cui bono? Toomas Hendrik Ilves / @ilvestoomas : The software side of China's supply chain attack. It wasn't just hardware. An online portal for firmware updates hid and distributed malware http://www.bloomberg.com/... via @BW Zack Whittaker / @zackwhittaker : Facebook: “In 2015, we were made aware of malicious manipulation of software related to Supermicro hardware from industry partners through our threat intelligence industry sharing programs.” http://www.bloomberg.com/...
Context & Ripple Effects
This lands days after Bloomberg Businessweek's report that malicious chips were found on Supermicro boards, and it widens the attack surface being alleged: beyond hardware implants, sources now describe a breach of Supermicro's own firmware update portal in 2015 that pushed malware to customers who pulled updates from it. Facebook is the most prominent named downloader, though it says none of the affected machines reached production.
The claim matters because firmware distribution is the trust anchor for an entire server fleet — if the update channel itself is compromised, every downstream audit of the boards has to be redone. Two days later, security expert Yossi Appleboum produced documents allegedly showing Supermicro shipped hacked hardware to a major US telco, and the stock fell more than 20%, showing how quickly unverified sourcing claims translate into market punishment.
First-order effects
- Facebook must account publicly for why its infrastructure touched the compromised update channel, while insisting no affected servers were used in production — a distinction that keeps the operational damage contained but keeps it answering supply-chain questions.
- Supermicro faces simultaneous pressure on two fronts: the firmware-portal breach undermines confidence in its software distribution, and the Appleboum allegations plus the stock drop put its hardware sales under scrutiny at once.
Second-order effects
- Hyperscale buyers have reason to treat vendor firmware portals as attack surface in their own right, favoring suppliers whose update chains they can verify independently — a shift that benefits rival server vendors even where no implant is ever proven.
- The pattern compounds: researchers later showed weaknesses in Supermicro hardware would allow a persistent hidden backdoor on IBM's cloud bare-metal servers (Ars Technica), meaning each new allegation forces re-examination of deployments already in the field, not just future purchases.
Third-order effects
- If US investigators' claims that Supermicro hardware carried backdoor chips as late as 2018 hold up (the 2021 reporting), procurement at cloud providers and governments structurally separates from lowest-cost assembly toward audited, geographically diversified supply — the seedbed of second-source and sovereign-compute strategies.
- Repeated unprovable-but-consequential allegations create their own regime: buyers will demand attestation and chain-of-custody for firmware and components regardless of whether any single claim is confirmed, because the reputational cost of being wrong exceeds the cost of verification.
The trend: Server supply chains are becoming a geopolitical trust problem, pushing large compute buyers from price-based procurement toward verifiable, multi-source hardware and firmware provenance.