Off the top of my head from that time, I remember they asked someone about the plausibility of some part of the story about the component types that might have been altered, he pointed them at some random example from Digi-Key, and that example became their photoshoot prop.
All of their photos were provably fake and staged, and made no technical sense.
There was that whole sub-story about how supposedly Ethernet jacks having metal shields was one of the indicators of compromise (what? almost every piece of datacenter kit uses Ethernet jacks with metal shields).
The more you looked into the details, the less they added up.
The only thing we could confirm was that, at some point, Supermicro shipped compromised drivers. That part I can absolutely believe, and like the last bit of this story update claims, that may well have been an APT hack from a state-actor. That side of the story is entirely believable and self-consistent.
But the hardware modifications? Sorry, but the way that story has been reported is complete garbage. I'm not saying it isn't true, I'm saying Bloomberg provided no credible evidence that it is true, and plenty of evidence that they don't have the slightest clue what they're doing, and that their reporting is dishonest.
Originally I gave them the benefit of the doubt, but when they published the Ethernet jack story with less than 5 days to check anything from that guy, they lost all semblance of credibility.