Apple Tells Congress 'Nothing Was Ever Found' to Suggest Alleged Supply Chain-Based Hack - MacRumors
Skip to Content

Apple Tells Congress 'Nothing Was Ever Found' to Suggest Alleged Supply Chain-Based Hack

Apple's top security chief told the U.S. Congress on Sunday that it had found no indication of suspicious transmissions or other evidence that its China supply chain was ever compromised (via Reuters).

the big hack bloomberg
In a letter to the Senate and House commerce committees, Apple Vice President for Information Security George Stathakopoulos wrote that the company had repeatedly investigated and found no evidence to support Bloomberg Businessweek's bombshell report that alleged tiny chips were discovered inside Apple servers which allowed for backdoor transmissions to Chinese spies.

"Apple's proprietary security tools are continuously scanning for precisely this kind of outbound traffic, as it indicates the existence of malware or other malicious activity. Nothing was ever found," he wrote in the letter provided to Reuters.

Stathakopoulos repeated Apple's statements to the press that it had never found any such planted chips or been contacted by the FBI over the alleged matter. The letter follows a statement issued on Saturday by the U.S. Department of Homeland Security saying it had no reason to doubt the companies who denied that they had ever discovered the tiny chips.

Apple, Amazon, and Supermicro all strongly rebutted the report, which alleged that Chinese intelligence planted microchips in Supermicro servers, which Apple and Amazon previously used in their data centers.

Despite the denials, which are also backed by the UK's national cyber security agency, retired Apple general counsel Bruce Sewell, and other unnamed Apple senior executives, Bloomberg said it stood by its report as of Friday, but didn't immeditately respond to requests for comment on Sunday.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Popular Stories

iPhone 17 Review Thumb 3

Apple Slashes iPhone 17 Prices in China for Annual 618 Festival

Friday May 15, 2026 7:09 am PDT by
Apple has slashed prices on the iPhone 17 Pro series in China by 1,000 yuan (around $138) in anticipation of the annual 618 shopping festival, one of the country's largest mid-year online retail events. The cuts went live on Friday on JD.com and Tmall, with Apple's official store on the latter platform applying a direct 1,000-yuan discount on the iPhone 17 Pro series. On JD.com, taking into ...
Aston Martin CarPlay Ultra Screen

Apple Says CarPlay Ultra is Coming to These Vehicle Brands

Thursday May 21, 2026 11:53 am PDT by
Last year, Apple launched CarPlay Ultra, the long-awaited next-generation version of its CarPlay software system for vehicles. Nearly a year later, CarPlay Ultra is still limited to Aston Martin's latest luxury vehicles, but that should change fairly soon. In May 2025, Apple said many other vehicle brands planned to offer CarPlay Ultra, including Hyundai, Kia, and Genesis. CarPlay Ultra...
iOS 27 on iPhone 17 1

iOS 27 Beta Available Tomorrow With These 12 New Features

Sunday June 7, 2026 8:39 am PDT by
Apple is set to unveil iOS 27 during its WWDC 2026 keynote this Monday, and there are many rumored features and changes for iPhones. The first developer beta of iOS 27 will likely be available immediately following the keynote, and a public beta typically follows in July. Following beta testing, the software update should be released to all users with a compatible iPhone in September....

Top Rated Comments

Scottsoapbox Avatar
100 months ago
There are many ways to mask communications. I'm not surprised they found nothing.
Name one undetectable by common practices.

Fortune 500 companies employ teams of IT security experts. So please enlighten us armchair hacker.
Score: 20 Votes (Like | Disagree)
BaltimoreMediaBlog Avatar
100 months ago
This is a Dog & Pony Show. If there's an ongoing investigation, #1, they rarely will even tell you. #2 Apple and others might not even know about it. It's even possible no one will ever know if its a vulnerability that is still existing and could be done again. The government never confirms stuff like this and strongly warns companies to do the same while secretly working behind the scenes. Everyone would be told to DENY ANYTHING. If we do find out anything, it will only be AFTER any possible issue is resolved, not during. Could be years!
Score: 18 Votes (Like | Disagree)
100 months ago
Bloomberg joining #fakenews now? Sad!
Score: 15 Votes (Like | Disagree)
Scottsoapbox Avatar
100 months ago
No serious hacker enters through the front door. Thinking outside the box is all the fun. I mentioned the LZ4 frame format above, but even SSH, generally considered secure, also has the potential for abuse (although admittedly it is more difficult). The initial key exchange initialization (called a kexinit packet) contains some fields that are, in my experience, usually ignored. The potential is there for abuse as well. Generally, communication originating internally is a much more difficult thing to contain, but it certainly isn't impossible.

:rolleyes: I'm actually Security+ certified, so maybe I know a little more than you do.
Wow a certification! How many *weeks* was the class for that? I mean the exam has 90 whole questions. :rolleyes:

You know some people get whole degrees from accredited universities in this stuff.

Again you didn't list an undetectable way to communicate massive data with China. You listed areas that "abuse" could occur. Malware doing something is one thing. Malware on thousands of servers transmitting back to the motherland without any notice of the outbound traffic is something completely different.
Score: 13 Votes (Like | Disagree)
AngerDanger Avatar
100 months ago
That diagram and entire article looks like something out of a 1993 Popular Mechanics magazine.
And from a quick glance, it looks like the illustrations depict china hacking our pencils!



Attachment Image
Score: 11 Votes (Like | Disagree)
Markoth Avatar
100 months ago
Wow a certification! How many *weeks* was the class for that? I mean the exam has 90 whole questions. :rolleyes:

You know some people get whole degrees from accredited universities in this stuff.

Again you didn't list an undetectable way to communicate massive data with China. You listed areas that "abuse" could occur. Malware doing something is one thing. Malware on thousands of servers transmitting back to the motherland without any notice of the outbound traffic is something completely different.
I have a degree from an accredited university, and I also have multiple certifications. I can send you the certs in an email if you're curious.

Insulting the Security+ makes you look foolish, so please continue.
Score: 11 Votes (Like | Disagree)