Kaspersky Lab Says Report Claiming China Hacked Apple's Former Server Supplier is Likely 'Untrue'

Russia-based cybersecurity company Kaspersky Lab today said that while "hardware supply chain attacks are a reality," evidence suggests Bloomberg Businessweek's report about Chinese intelligence tampering with server motherboards manufactured by Apple's former supplier Supermicro is "untrue."

Apple Data Center

Apple data center

Kaspersky Lab said the report "should be taken with a grain of salt" in its 14-page analysis of the alleged attack, obtained by MacRumors:

The stories published by Bloomberg in October 2018 had a significant impact. For Supermicro, it meant a 40% stock valuation loss. For businesses owning Supermicro hardware, this can be translated into a lot of frustration, wasted time, and resources. Considering the strong denials from Apple and Amazon, the history of inaccurate articles published by Bloomberg, including but not limited to the usage of Heartbleed by U.S. intelligence prior to the public disclosure, as well as other facts from these stories, we believe they should be taken with a grain of salt.

Kaspersky Lab added that the language in both Apple and Amazon statements denying the Bloomberg Businessweek report are "pretty strong" and "leaves little to no chance of retractions or denials at a later time." The firm added that the statements are regulated by the SEC in the United States.

The key part of Apple's statement was as follows:

On this we can be very clear: Apple has never found malicious chips, "hardware manipulations" or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement.

In a press release, Apple later said it is not under any kind of gag order or other confidentiality obligations.

Referring to Apple's mid-2016 detection of malware-infected firmware in specific Supermicro servers that were used internally only, Kaspersky Lab said it believes it is "quite possible that the Bloomberg journalists misunderstood the incident and included it in the hardware supply chain attack story."

The analysis said hardware-based attacks like the one alleged in the Bloomberg Businessweek report are sophisticated, difficult to implement, and expensive. "For instance, even if a server board is compromised during manufacturing, it is complicated to ensure that it finds its way to a certain target."

The accuracy of Bloomberg Businessweek's report has been questioned by not only Kaspersky Lab, but the Department of Homeland Security, the U.K.'s National Cyber Security Centre, and NSA senior advisor Rob Joyce.

Moreover, Apple's recently retired general counsel Bruce Sewell said he called the FBI's then-general counsel James Baker last year after being told by Bloomberg of an open investigation into Supermicro, and was told that nobody at the federal law enforcement agency knew what the story was about.

Apple's aggressive campaign to deny the report extends to unnamed senior executives within the company. Supermicro and Amazon, also named in the report, have likewise issued strongly-worded denials of the report.

Bloomberg Businessweek continues to stand by its reporting, and has since followed up with a second story that claims a major U.S. telecommunications company discovered manipulated hardware from Supermicro in its network and removed it in August, citing a security expert working for the telecom company.

The original report, citing 17 unnamed sources, claimed that Chinese spies planted tiny chips the size of a pencil tip on server motherboards manufactured by Supermicro at its Chinese factories. The servers were then sold to companies such as Apple and Amazon for use in their respective data centers.

An unnamed government official cited in the report said China's goal was "long-term access to high-value corporate secrets and sensitive government networks," but no customer data is known to have been stolen.

The report claimed that Apple discovered the suspicious chips on the motherboards around May 2015, after detecting odd network activity and firmware problems. Two senior Apple insiders were cited as saying the company reported the incident to the FBI, but kept details about what it had detected tightly held.

Apple dropped Supermicro as a supplier in 2016, after the incident with the malware-infected firmware updates.

We've covered Bloomberg Businessweek's report in extensive detail over the past week, with all of our coverage available in our "The Big Hack" archive. At this point, it remains a stalemate between Apple and Bloomberg.

Kaspersky Lab itself has faced controversy, with several reports over the last year claiming its software was compromised by Russian intelligence. Nevertheless, Motherboard said the firm "continues to have a good reputation in the industry," particularly as it relates to its ability to discover malware.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Popular Stories

iOS 26

When Will Apple Release iOS 26.2?

Monday December 1, 2025 4:37 pm PST by
We're getting closer to the launch of the final major iOS update of the year, with Apple set to release iOS 26.2 in December. We've had three betas so far and are expecting a fourth beta or a release candidate this week, so a launch could follow as soon as next week. Past Launch Dates Apple's past iOS x.2 updates from the last few years have all happened right around the middle of the...
ios 18 to ios 26 upgrade

Apple Pushes iPhone Users Still on iOS 18 to Upgrade to iOS 26

Tuesday December 2, 2025 11:09 am PST by
Apple is encouraging iPhone users who are still running iOS 18 to upgrade to iOS 26 by making the iOS 26 software upgrade option more prominent. Since iOS 26 launched in September, it has been displayed as an optional upgrade at the bottom of the Software Update interface in the Settings app. iOS 18 has been the default operating system option, and users running iOS 18 have seen iOS 18...
maxresdefault

iPhone Fold: Launch, Pricing, and What to Expect From Apple's Foldable

Monday December 1, 2025 3:00 am PST by
Apple is expected to launch a new foldable iPhone next year, based on multiple rumors and credible sources. The long-awaited device has been rumored for years now, but signs increasingly suggest that 2026 could indeed be the year that Apple releases its first foldable device. Subscribe to the MacRumors YouTube channel for more videos. Below, we've collated an updated set of key details that ...
iOS 26

Apple Seeds iOS 26.2 and iPadOS 26.2 Release Candidates to Developers and Public Beta Testers

Wednesday December 3, 2025 10:33 am PST by
Apple today seeded the release candidate versions of upcoming iOS 26.2 and iPadOS 26.2 updates to developers and public beta testers, with the software coming two weeks after Apple seeded the third betas. The release candidates represent the final versions of iOS 26.2 and iPadOS 26.2 that will be provided to the public if no further bugs are found during this final week of testing....
iphone 17 cyber

iPhone 17 Demand Is Breaking Apple's Sales Records

Tuesday December 2, 2025 9:44 am PST by
Apple's iPhone 17 lineup is selling well enough that Apple is on track to ship more than 247.4 million total iPhones in 2025, according to a new report from IDC. Total 2025 shipments are forecast to grow 6.1 percent year over year due to iPhone 17 demand and increased sales in China, a major market for Apple. Overall worldwide smartphone shipments across Android and iOS are forecast to...
Photos App Icon Liquid Glass

John Gruber Shares Scathing Commentary About Apple's Departing Software Design Chief

Thursday December 4, 2025 9:30 am PST by
In a statement shared with Bloomberg on Wednesday, Apple confirmed that its software design chief Alan Dye will be leaving. Apple said Dye will be succeeded by Stephen Lemay, who has been a software designer at the company since 1999. Meta CEO Mark Zuckerberg announced that Dye will lead a new creative studio within the company's AR/VR division Reality Labs. On his blog Daring Fireball,...
Touchscreen MacBook Feature

Here Are the Four MacBooks Apple Is Expected to Launch Next Year

Monday December 1, 2025 5:00 am PST by
2026 could be a bumper year for Apple's Mac lineup, with the company expected to announce as many as four separate MacBook launches. Rumors suggest Apple will court both ends of the consumer spectrum, with more affordable options for students and feature-rich premium lines for users that seek the highest specifications from a laptop. Below is a breakdown of what we're expecting over the next ...
iphone air camera

iPhone Air's Resale Value Has Dropped Dramatically, Data Shows

Thursday December 4, 2025 5:27 am PST by
The iPhone Air has recorded the steepest early resale value drop of any iPhone model in years, with new data showing that several configurations have lost almost 50% of their value within ten weeks of launch. According to a ten-week analysis published by SellCell, Apple's latest lineup is showing a pronounced split in resale performance between the iPhone 17 models and the iPhone Air....
iPhone 17 Pro Cosmic Orange

iPhone 17 Pro Lost a Camera Feature Pro Models Have Had Since 2020

Thursday December 4, 2025 5:18 am PST by
iPhone 17 Pro models, it turns out, can't take photos in Night mode when Portrait mode is selected in the Camera app – a capability that's been available on Apple's Pro devices since the iPhone 12 Pro in 2020. If you're an iPhone 17 Pro or iPhone 17 Pro Max owner, try it for yourself: Open the Camera app with Photo selected in the carousel, then cover the rear lenses with your hand to...
chatgpt logo

Sam Altman Declares 'Code Red' for ChatGPT, Delays OpenAI Advertising Plans

Tuesday December 2, 2025 3:30 pm PST by
OpenAI is deprioritizing work on advertising as it focuses on improving the quality of ChatGPT, reports The Information. OpenAI CEO Sam Altman declared a "code red" on Monday, and told employees that the company needs to improve ChatGPT so it doesn't fall behind competitors like Google and Anthropic. Altman said that OpenAI needs to work on personalization for each user, image generation,...

Top Rated Comments

BaltimoreMediaBlog Avatar
93 months ago
Sure, yeah, right. I'll trust the Russians on Chinese spying! HAHAHAHAHA!

That's like trusting Tim Cook when he says, "There are no FM radios in iPhones" during a hurricane when independent tech firms have already found the FM circuitry! :D
Score: 17 Votes (Like | Disagree)
Scottsoapbox Avatar
93 months ago
Bloomberg needs to show some actual proof at this point.
Score: 14 Votes (Like | Disagree)
mariusignorello Avatar
93 months ago
This is the Ford vs. Kavanaugh of technology. Put up proof or be done with it.

Unnamed sources, here say and the likes are not proof.
Score: 12 Votes (Like | Disagree)
parseckadet Avatar
93 months ago
This is the same Kaspersky Labs that was found to be sending consumer data to the former KGB right? Yeah, they’re super trustworthy.
Score: 10 Votes (Like | Disagree)
Solomani Avatar
93 months ago
The Russians are defending the Chinese in their alleged attacks on American (companies).

Haha. This is rich.
Score: 6 Votes (Like | Disagree)
StevieD100 Avatar
93 months ago
Hopefully Apple and Amazon can sue them into bankruptcy. Cook needs a new tortoise shell eyeglasses, and Bezos needs a new pair of pants.
If Apple had any sense at all, they would not go anywhere near filing suit against Bloomberg.
BB's exec and by implication their lawyers would just love to get their hands on all sorts of confidential Apple documents and the like. They'd be in rumour heaven and to hell with the fines.
I read a book by a Law Professor a few years ago as part of my MBA. The words he said about Discovery really made me think.
"Beware the Ides of Discovery"
You can be compelled to turn over almost every document (paper and electronic) that exists inside the company even if it really has nothing to do with the law suit, just in case it does and ...
There is a reason why many cases never get to trial and that is Discovery. One side will see that they basically have no chance of winning. Or that they must settle out of court or all their internal dirty linen will get read out in court and basically become public domain.
for a company as secretive as Apple, filing suit against Qualcomm is far less risky in terms of leaks etc than it is to file again Bloomberg who are in the business of publishing 'secret and lies'
Score: 5 Votes (Like | Disagree)