REvil ransomware gang says it had breached Acer, sharing leaked images of internal docs on the dark web, and is demanding $50M; Acer says it is investigating
Taiwanese computer maker Acer has suffered a ransomware attack over the past weekend at the hands of the REvil ransomware gang …
Context & Ripple Effects
REvil's claim against Acer follows a now-familiar script for the gang: post images of stolen internal documents on its dark web blog, name an eye-watering figure, and let the countdown pressure the target. A $50M demand would put this among the largest single ransoms ever publicly sought at that point.
The pattern did not stop at Acer. Within weeks REvil hit Apple contractor Quanta Computer with another $50M threat over leaked product schematics, and by July it escalated to the Kaseya supply-chain attack, claiming 1M+ infected systems and asking $70M for a universal decryptor — each move raising the ceiling for what a top-tier crew will ask.
First-order effects
- Acer is forced into incident response while internal documents sit exposed on REvil's leak site, giving the gang leverage regardless of whether systems are actually encrypted.
Second-order effects
- Other Taiwanese hardware makers in REvil's crosshairs — Quanta being breached a month later shows the gang working through the same ODM supply base — must assume their brand-name customers' data can be used as extortion leverage against them.
Third-order effects
- The escalation from $50M single-victim demands to a $70M mass-decryptor price after the Kaseya attack marks the shift from opportunistic encryption to 'big game hunting' via supply-chain compromise, pushing ransomware toward the center of cyber-insurance underwriting and national security policy.
The trend: Ransomware crews like REvil are scaling from one-off corporate breaches to supply-chain attacks with eight-figure demands, using leaked-document shaming as standard leverage.