/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

REvil ransomware gang says it had breached Acer, sharing leaked images of internal docs on the dark web, and is demanding $50M; Acer says it is investigating

Taiwanese computer maker Acer has suffered a ransomware attack over the past weekend at the hands of the REvil ransomware gang …

The Record Catalin Cimpanu

Context & Ripple Effects

REvil's claim against Acer follows a now-familiar script for the gang: post images of stolen internal documents on its dark web blog, name an eye-watering figure, and let the countdown pressure the target. A $50M demand would put this among the largest single ransoms ever publicly sought at that point.

The pattern did not stop at Acer. Within weeks REvil hit Apple contractor Quanta Computer with another $50M threat over leaked product schematics, and by July it escalated to the Kaseya supply-chain attack, claiming 1M+ infected systems and asking $70M for a universal decryptor — each move raising the ceiling for what a top-tier crew will ask.

First-order effects

  • Acer is forced into incident response while internal documents sit exposed on REvil's leak site, giving the gang leverage regardless of whether systems are actually encrypted.

Second-order effects

  • Other Taiwanese hardware makers in REvil's crosshairs — Quanta being breached a month later shows the gang working through the same ODM supply base — must assume their brand-name customers' data can be used as extortion leverage against them.

Third-order effects

  • The escalation from $50M single-victim demands to a $70M mass-decryptor price after the Kaseya attack marks the shift from opportunistic encryption to 'big game hunting' via supply-chain compromise, pushing ransomware toward the center of cyber-insurance underwriting and national security policy.

The trend: Ransomware crews like REvil are scaling from one-off corporate breaches to supply-chain attacks with eight-figure demands, using leaked-document shaming as standard leverage.

Discussion

  • @hackinggavin @hackinggavin on x
    ⚠️ What if your company was asked to pay $50 million to get back its data? This is happening to Acer! Recently I spoke to some managers about how much ransomware could cost them if they are not proactive. This is real life. https://therecord.media/... https://twitter.com/...
  • @lisagshort @lisagshort on x
    At some point - it only becomes a reality if the money is paid. We must all wonder what will happen if their threats are met with “go ahead - we are not paying” https://twitter.com/...