Broadcom hit by employee data theft after breach in supply chain


- Business Systems House was breached in September
- It is a business partner of ADP, which serviced Broadcom at one point
- Now, sensitive Broadcom files seem to have emerged on the dark web
Customers of the global semiconductor giant Broadcom have had their sensitive data leaked on the dark web after a two-step supply chain attack. Apparently, a company called Business Systems House (BSH), a human capital management (HCM) services provider from the Middle East, suffered a ransomware attack in September 2024, in which a group known as El Dorado (later rebranded as BlackLock), stole its files.
This firm is a business partner of payroll company ADP which, in turn, worked with Broadcom. In fact, the chip giant was in the process of switching payroll providers when the incident happened, meaning it almost dodged that bullet.
However, in December 2024, the two firms discovered the stolen data on the internet. “Because the data taken by the criminal actor was in an unstructured format, definitively determining which employees were impacted and, for each employee, which data fields were disclosed, was a lengthy process for BSH/ADP, and this information was not made available to Broadcom until May 12, 2025,” it was explained.
El Dorado or BlackLock
According to The Register, who first broke the story, the attackers made away with the following data:
- National ID numbers
- National health insurance ID numbers
- Health insurance policy/ID numbers
- Financial account numbers
- Dates of birth
- Salary details
- Employment termination date
- Personal email addresses
- Personal phone numbers
- Home addresses
Broadcom urged everyone to turn on MFA and any other security settings that their financial institutions provide. Furthermore, it warned users to monitor their financial records.
You’ll be forgiven for not knowing who El Dorado is. It is a relatively new ransomware operation, emerging in March 2024, and already rebranded to BlackLock. The files stolen from Broadcom were posted on the BlackLock leak site, as well. Allegedly, the group consists of Russian-speaking individuals.
Broadcom serves a diverse range of customers across various industries, including technology, finance, healthcare, and telecommunications. Some of the biggest names include Apple, Samsung, Cisco, British Airways, and many others. ADP, The Register claims, is no worse, but so far, no one reported losing data.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via The Register
You might also like
Business Systems House was breached in September It is a business partner of ADP, which serviced Broadcom at one point Now, sensitive Broadcom files seem to have emerged on the dark web Customers of the global semiconductor giant Broadcom have had their sensitive data leaked on the dark web after…
Recent Posts
- Android 16’s answer to iOS Live Activities is coming soon – here are the apps it’ll support, including Google Maps
- Laid-off workers should use AI to manage their emotions, says Xbox exec
- Hundreds of Android apps band together in massive scam campaign targeting millions – here’s what we know
- GM’s Cruise Cars Are Back on the Road in Three US States—But Not for Ride-Hailing
- The Ploopy Knob is an open-source control dial for your PC
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021