ASUS Listed by Everest Ransomware Group, 1 TB Data Stolen

The Everest ransomware group claims it has breached ASUS and stolen more than 1 TB of internal data, including what it describes as "camera source code." The allegation was posted on the group's dark-web leak site on December 2. Everest says the data includes internal documents, engineering material, and other confidential files, and is demanding that ASUS contact them via the encrypted platform Qtox. No ransom amount has been disclosed. In this context, "camera source code" likely refers to firmware or low-level software used in ASUS devices with integrated cameras (smartphones, laptops) such as drivers, applications related to image processing, or internal developer tools. Everest's past operations often focus on stealing technical IP and development archives before attempting any encryption, a strategy meant to maximize leverage even if victims can recover systems from backups.

ASUS initially did not confirm or deny the breach. However, the company has now issued a public statement saying that an external supplier, not ASUS itself, was compromised. According to ASUS, the incident exposed some camera-related source code used in ASUS phones, but did not impact ASUS products, internal systems, or customer data. The company says it is strengthening supply-chain security and remains compliant with cybersecurity standards.
Public Statement Regarding Unauthorized Third-Party Data Access
An ASUS supplier was hacked. This affected some of the camera source code for ASUS phones. This incident has not impacted ASUS products, internal company systems, or user privacy. ASUS continues to strengthen supply chain security in compliance with cybersecurity standards.
Read full story