WannaCry Outbreak Could Cost TSMC $170M
sensorstechforum.com
sensorstechforum.com
>> Since data integrity and confidential information haven’t been compromised, the company believes the attack wasn’t the work of a hacker
>> According to CEO C.C. Wei, the attack is purely due to the company’s own negligence. Wei also said that he doesn’t think there is any hacking behavior involved.
Those three lines sum up the article.
From a different article, the virus got onto their network when they installed some type of new software/tool. They didn't check it before they deployed it, turns out it had wannacry on it. Since the networks this virus infected weren't internet connected, it didn't hit the kill-switch domain. So it was left to run wild until they contained it.
https://www.databreachtoday.com/wannacry-outbreak-hits-chipm...
> patching is not always an easy endeavor in manufacturing environments because any code changes must be rigorously tested to ensure they don't have a real-world impact - for example on industrial control systems or supervisory control and data acquisition systems, which control the software and hardware that runs manufacturing processes. Indeed, ICS and SCADA systems may have a lifespan of 20 to 30 years. Many were never designed to be internet connected.
Edit: That's not to say the machines should be connected to the internet; I'm just explaining the circumstances that allowed this to occur.
This makes is sound like Marcus Hutchins was responsible for WannaCry, which is incorrect.