Analog Devices: Cyberattack and Extortion Over 570,000 Records

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/4 · Initial Access

Attackers gained unauthorized access to certain Analog Devices company systems.

  • Discovered on June 23, 2026 by Analog Devices itself
  • Specific attack vector not officially known (no CVE, no IoCs)
  • Affected systems not specified in SEC Form 8-K
PHASE 2/4 · Collection

Files were gathered from the compromised systems for theft.

  • Investigation found that files from affected systems were involved
  • Type of data (customer, employee data or IP/chip designs) unknown
  • ExfilSquad claims 570,000 records with customer PII and addresses
PHASE 3/4 · Exfiltration

It was confirmed that files were exfiltrated from the affected systems.

T1567 – Exfiltration Over Web Service
  • Analog Devices confirms exfiltration of files in SEC filing
  • ExfilSquad operates on an 'exfiltration-only' model without encryption
  • To their knowledge, data not publicly released or used fraudulently
PHASE 4/4 · Impact / Extortion

ExfilSquad threatened to publish the stolen data to extort a ransom.

T1657 – Financial Theft
  • On July 26, 2026 ExfilSquad listed 15 victims simultaneously on its Tor leak site
  • Other alleged targets: Microsoft, Wesco International, cities of Atlanta and Houston, Frontier Airlines, Allstate
  • Analog Devices removed from the leak site on July 29 – possible sign of negotiations
  • Business operations reportedly never interrupted per Analog Devices
Short & clear answers
Frequently asked questions about this incident
Am I affected by the breach as a business partner of Analog Devices?
Analog Devices itself is directly affected. If your company, as a customer, supplier or partner, has transmitted personal data (such as details of procurement staff or contacts) to Analog Devices, that data could be part of the stolen files. Exactly which types of data were taken is not yet officially known—Analog Devices only confirms that files were exfiltrated.
What do I need to do right now?
Check whether your company has transmitted business data to Analog Devices, and monitor your email for official notifications from analog.com. Change passwords for all systems connected to Analog Devices and enable two-factor authentication everywhere. If personal data is affected, inform your data protection officer immediately.
Do I have to report the incident to the data protection authority?
If personal data of your customers or employees is affected, the 72-hour reporting deadline under Art. 33 GDPR applies toward your competent state data protection authority. Where there is a high risk to the individuals affected, a notification of those persons under Art. 34 GDPR is also required. Carefully document any notification you receive from Analog Devices.
How credible are the ExfilSquad group's claims of 570,000 stolen records?
The figure of 570,000 records is a claim made by the attackers—not a confirmed fact. Security firm SOCRadar urges caution and currently considers fabrication more likely, as no forensic evidence, verifiable data samples or independent confirmation have been provided. Analog Devices was also removed from the leak site again on July 29.
How can I check whether company email addresses appear in the leak?
Use free services like Have I Been Pwned (haveibeenpwned.com), which show whether company email addresses have surfaced in known data leaks. Threat intelligence sources such as ransomware.live or SOCRadar track whether ExfilSquad posts new releases regarding Analog Devices. The SEC EDGAR portal (filing type 8-K) also provides official updates on the scope.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.