Cyber Incident Victim: Analog Devices Inc.
Timeline
Summary
Analog Devices confirmed unauthorized actors accessed systems and exfiltrated files, triggering incident response, expert involvement, and law enforcement notification without interrupting operations. The company did not identify the threat actor, method, or affected systems, and has not determined the full scope of the stolen data, noting no evidence of public release or fraudulent use. It continues to monitor for misuse and will notify affected parties as required, saying the incident is unlikely to materially impact business but acknowledging the assessment could change. A separate cybersecurity matter reported is under review.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Analog Devices, Inc. detected a cyber incident on June 23, 2023. Upon detection, the company activated its incident response protocols. Analog Devices enlisted external cybersecurity experts to assist with containment and forensic investigations. The company also notified law enforcement authorities about the incident. Analog Devices reported that its operations were not interrupted during the cyberattack. The company did not identify the threat actor responsible for the intrusion. Analog Devices did not disclose the intrusion method used by the attackers. The company did not specify which systems or network environments were affected. The investigation revealed that certain files were taken from the impacted systems. Analog Devices has not yet determined the full nature and scope of the exfiltrated information.

As of the filing, the company stated it had no evidence that the stolen data had been publicly released or used for fraudulent purposes. Analog Devices committed to continue monitoring for signs of misuse of the exfiltrated files. The company said it would take appropriate action if any indicators of malicious activity arise. Analog Devices vowed to notify affected parties and relevant regulators as required by law. Based on the information available and the containment measures implemented, the company believes the June cyberattack is unlikely to materially affect its business, operations, or financial condition. Analog Devices noted that this assessment may change as the investigation progresses, especially if the stolen material includes sensitive proprietary data, regulated personal information, or information related to customers and supply-chain partners. The SEC filing also mentions a separate cybersecurity matter reported publicly on July 26, 2023. Analog Devices described this July 26 event as disparate and unrelated to the June 23 intrusion. The company is assessing the validity, scope, and potential impact of the July 26 reports but has provided no further details. It remains unclear whether the July 26 reports involve a data leak, a separate allegation of unauthorized access, or activities linked to a known ransomware or extortion group.
Analog Devices has not provided a timeline for completing its investigation or releasing further technical details about either incident.
