One of the world's largest electronics manufacturers confirmed a cyberattack, after a ransomware group claimed it had taken 11 million records.
The gap between what an attacker claims and what a company confirms is routine in these cases, and it's worth understanding why. The attacker has an interest in inflating the number to increase pressure; the company has an interest in keeping estimates low until certain, because every confirmed record carries regulatory cost.
A global-scale electronics manufacturer is a target with particular appeal: it holds specifications for unreleased products, production schedules for customers who are major brands, and contracts with negotiated pricing.
Attacks on software suppliers and industrial environments followed that logic all year: the value isn't in the affected company's data, it's in what that data reveals about its customers.
For anyone depending on a manufacturing supplier, the question usually missing from the contract is exactly that: what information of ours sits in their system, and how quickly are we told if it leaks.
