← Taiwan Semiconductor

2018 TSMC — WannaCry-class virus spread from misconfigured new-tool onboarding; fabs offline temporarily (~3% Q3 revenue guide) (Aug)

2018 10.0K records affected Share on X

Data compromised

TSMC asserted production integrity and customer data stores were not touched—impact was operational uptime

Technical writeup

TSMC publicly stated a computer-virus outbreak began the evening of August 3, 2018, knocking offline varying fractions of fab tools until roughly four-fifths of impacted tools were restored by August 5 and full restoration was targeted for August 6. Management attributed the outbreak to misoperation during software installation for a new tool that was connected without adequate scanning, letting a WannaCry family variant propagate across Windows 7–controlled tool chains. TSMC emphasized customer confidential information was not compromised while guiding roughly 3% Q3 revenue and ~1 ppt gross-margin impact. ZDNet reiterated TSMC’s description that unpatched Windows interfaces on manufacturing equipment amplified spread.

Root cause

Provisioning hygiene failure (unvetted tool image + weak patch posture on manufacturing Windows endpoints)

References