Micro-Star International disclosed a network incident in April 2023 following a ransomware attack. The company said it had reported the matter to law enforcement, urged customers to obtain firmware only from its official site, and did not enumerate what had been taken.
After the company declined to pay, the operators published the stolen material. Security researchers examining the leak reported that it contained private firmware image signing keys and private keys for Intel Boot Guard.
Why This File Is Graded Medium
The desk grades on what the record establishes, not on how alarming a finding is. The intrusion is established and the vendor confirmed it. The key compromise is not the vendor’s statement — it is analysts’ characterisation of data published by an extortion group, and MSI has not confirmed the scope.
That is a real gap. Data published by an attacker after a refusal is exactly the material with the strongest incentive to be exaggerated or salted, and the desk’s standing rule is that a leak-site artefact is evidence of a claim rather than evidence of a fact.
What A Boot Guard Key Would Mean
Intel Boot Guard is a hardware-anchored check that firmware is signed by the platform manufacturer. A private key for it would let signed firmware be produced that a machine treats as genuine, below the operating system and below anything installed on it.
Reporting placed one affected key as present on devices from several other manufacturers, which is what makes this a supply chain file rather than a vendor file. The corpus records the same class of trust-primitive failure at 23-0329, where a valid signature attested to a malicious build, and at 23-0711, where a trusted key signed forged tokens.
Keys Cannot Be Rotated Like Passwords
The reason this remains open rather than closed is that the remedy is not available. A signing key burned into shipped hardware cannot be rotated by an update in the way a credential can, and the affected population is machines already sold.
The corpus files the same irreversibility at 23-0518, where the only trustworthy remediation was replacing the appliance.
Built on contemporaneous reporting of MSI’s disclosure and on published analysis of the leaked material. The intrusion and MSI’s advice to obtain firmware only from official sources are the company’s. The presence and scope of firmware and Intel Boot Guard signing keys in the leak are researchers’ analysis of data published by the extortion group, and MSI did not confirm them; the file is graded medium for that reason. The 1.5TB volume and $4 million demand circulating in reporting originate with the operators and are deliberately absent from the record. No key material, hash or device identifier is reproduced. Corrections: corrections@forensicpost.com.
- MSI’s firmware, Intel Boot Guard private keys leakedHelp Net Security
- MSI Data Breach: Private Code Signing Keys Leaked on the Dark WebThe Hacker News