Analog Devices Discloses Data Breach After Hackers Stole Files in June Attack

The Massachusetts chip-maker told federal regulators that unauthorised intruders accessed its systems on 23 June and took files. A separate extortion group now claims to hold 570,000 records from the company.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Photoreal news-editorial style 16:9 photograph of rows of server racks inside a large data centre, bathed in cool blue and white light, with a single rack door
Share

Key points

  • Analog Devices, a semiconductor company with roughly 24,000 employees and $12 billion in annual revenue, detected unauthorised access to its systems on 23 June 2026.
  • The company filed a disclosure with the U.S. Securities and Exchange Commission (SEC) on Wednesday, as required under federal cybersecurity rules that took effect in December 2023.
  • Hackers stole files, but Analog Devices hasn't specified what kind of information was taken or how many people may be affected.
  • An extortion group calling itself ExfilSquad separately claims to have stolen 570,000 records from the company; Analog Devices says it's still assessing that claim.
  • The company says the breach didn't disrupt its operations and no stolen files have been found circulating publicly.

Analog Devices makes the small electronic chips that sit inside industrial machinery and communications equipment. The company is publicly traded and based in Massachusetts. On Wednesday it reported a security breach to the SEC, the federal agency that oversees public companies, in a filing now required when a company suffers a significant cyber incident.

What actually happened?

On 23 June, the company's security team detected intruders inside certain internal systems. Outside security experts confirmed that hackers had taken some files before being discovered.

Operations were never disrupted. As of the filing date, Analog Devices isn't aware of the stolen files being published online or used against anyone. Under the SEC's cybersecurity disclosure rules, which became mandatory in December 2023, public companies must report breaches judged to be material, meaning significant enough to affect investors or the business. Analog Devices stated the incident doesn't meet that threshold.

For context on what those disclosure obligations mean in practice, our 16 June 2026 coverage of cybersecurity regulation examined how the rules are being applied.

Is there a second threat?

Yes, and this is the part Analog Devices is still working out. The same SEC filing contains a carefully worded sentence: the company says it was made aware, on 26 July 2026, of public reports about "a disparate cybersecurity matter" it is currently assessing.

That almost certainly refers to claims by a group called ExfilSquad, which says it stole 570,000 records from Analog Devices. ExfilSquad focuses purely on stealing data rather than deploying ransomware, software that locks a victim's files until a ransom is paid. The group's public claims page has listed Microsoft, the cities of Atlanta and Houston, and the UK Department of Education as alleged victims.

Threat intelligence firm SOCRadar noted this week that some of ExfilSquad's past claims appear exaggerated or fabricated. Analog Devices no longer appeared on ExfilSquad's website at the time of publication, first reported by SecurityWeek. That pattern is worth watching: two weeks ago we reported that ShinyHunters made similarly unverified breach claims against Ernst and Young, and the evidence there also took time to pin down.

What should employees or customers watch for?

Analog Devices sells mainly to businesses, not consumers. Employees and individuals whose information may be held in company records should watch for unexpected emails referencing personal details, a common sign that stolen data is fuelling follow-up phishing, where criminals send fake messages to trick people into handing over passwords or financial information. Our guide to what a data breach means and how to protect yourself covers the practical steps.

If personal data was taken, notification laws will require Analog Devices to inform affected individuals directly.

Detail Information
Breach detected 23 June 2026
SEC filing date Wednesday, July 2026
ExfilSquad claim awareness date 26 July 2026
Records claimed stolen (ExfilSquad) 570,000
Operations disrupted No
Files found circulating publicly No

Common questions

Do I need to do anything if I am an Analog Devices customer?

The company sells to industrial and commercial clients, not directly to individual consumers. If you work for a business that deals with Analog Devices, ask your IT or security team whether any shared data could be involved, and watch for unusual emails referencing your organisation.

Why does a chip-maker have to tell the SEC about a hack?

Since December 2023, the SEC requires all publicly traded U.S. Companies to disclose cybersecurity incidents that are material, meaning incidents a reasonable investor would want to know about. The rule is designed to stop companies from burying breach news in footnotes years after the fact.

© 2026 Threat Vectr