Apple

The REvil ransomware gang has mysteriously removed Apple's schematics from their data leak site after privately warning Quanta that they would leak drawings for the new iPad and new Apple logos.

Earlier this month, the ransomware gang conducted an attack on Quanta, a Taiwan-based original design manufacturer (ODM) that helps manufacture the Apple Watch, Apple Macbook Air, and the Apple Macbook Pro.

As part of this attack, the threat actors stole data belonging to the company, including drawings and schematics for Apple products.

After not receiving a ransom payment from Quanta, which had a starting price of $50 million, REvil began posting schematics for Apple Macbooks on their data leak site.

As part of this leak, REvil warned Apple that they should buy back the data by May 1st or more data would be leaked.

REvil's warning to Apple about further leaks
REvil's warning to Apple about further leaks

REvil removes schematics from the data leak site

REvil is not known for being compassionate or giving up very easily, so it was a surprise to learn today that the ransomware gang removed the Quanta leak page, including Apple schematics and drawings, from their data leak site.

BleepingComputer has since seen a new private chat created between REvil and Quanta four days ago. In this private chat, REvil told Quanta that they hid the data leak page and will stop talking to reporters to allow negotiations to continue.

While BleepingComputer did not see any messages from a Quanta representative, REvil stated, "Having started a dialogue with us, you can count on a good discount."

This discount reduces the ransom demand from $50 million to $20 million and includes a deadline of May 7th, as shown by the image below.

New REvil ransom page for Quanta
New REvil ransom page for Quanta

REvil has since warned Quanta that they will begin to publish drawings for the "new iPad, new Apple logos" if they do not receive a response from Quanta.

A portion of the new REvil and Quanta chat
A portion of the new REvil and Quanta chat

It is unknown if Quanta is communicating with REvil within another chat or if negotiations have stalled.

If REvil once again begins leaking data, we will know whether Quanta paid the ransom or not.

Related Articles:

UnitedHealth confirms it paid ransomware gang to stop data leak

Ransomware payments drop to record low of 28% in Q1 2024

Optics giant Hoya hit with $10 million ransomware demand

Synlab Italia suspends operations following ransomware attack

HelloKitty ransomware rebrands, releases CD Projekt and Cisco data