Get the latest market trends in your inbox

Stay on top of the latest market trends and economic insights with the Axios Markets newsletter. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Denver news in your inbox

Catch up on the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Des Moines news in your inbox

Catch up on the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Minneapolis-St. Paul news in your inbox

Catch up on the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tampa Bay news in your inbox

Catch up on the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Charlotte news in your inbox

Catch up on the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Photo: Alfexe/via Getty Images

Last Thursday Bloomberg reported that authorities were investigating Supermicro, which manufactures server motherboards, for shipping equipment implanted with chips that China could use to spy on users.

The big picture: The piece was a bombshell, but a raft of vehement denials from everyone involved — including Apple and Amazon, which Bloomberg claimed discovered the secret chips in their own servers — has made the story increasingly hard to believe.

Why it matters: If the piece is a mistake, it is not a small one. Shares in Supermicro stock dropped more than 50% after the story, wiping away nearly $600 million in market cap. But this isn’t just about one firm’s fortunes — the kind of sabotage described in the story, if real, could compromise major institutions.

  • Supermicro products — and the web and cloud services fueled by them — are used by defense, banks, hospitals and other groups.
  • A state election official who spoke to Codebook was concerned that state accounts might have been made vulnerable to attack.

It's hard to believe that Amazon, Apple and Supermicro are all fabricating their emphatic denials of the Bloomberg story.

  • Some users dismissed the denials on Twitter, declaring “I can’t trust corporations” — a distrust that many tech companies have brought upon themselves.
  • But lawyers who spoke to Codebook said the detailed denials wouldn’t just be a public relations issue if incorrect or fudged.
  • “The companies [would] risk enforcement by the FTC for engaging in a deceptive act that is likely to harm consumers,” emailed David Vladeck, Georgetown professor and former head of the Federal Trade Commission’s Bureau of Consumer Protection, adding, “I am strongly disinclined to think they are lying.”
  • Apple would only have compounded its woes Monday by repeating its claims in a letter to two congressional committees.
  • Homeland Security and the British cybersecurity office, the National Cyber Security Centre also denied knowledge of Bloomberg’s claims.

The big question: Flustered cybersecurity pros have been left wondering how much of the story is accurate. The expert consensus is that it's more likely that Bloomberg is wrong than that the companies and government agencies are lying.

  • One key voice disapproving of the piece is security researcher Joe FitzPatrick, who is quoted in the story. According to the Risky Business podcast, FitzPatrick says he emailed Bloomberg before the article was published that their story "didn't make sense."

Bloomberg noted in a statement sent to Codebook Tuesday that Joe FitzPatrick had no direct knowledge that the story was incorrect.

  • "The specific ways the implant worked were described, confirmed, and elaborated on by our primary sources who have direct knowledge of the compromised Supermicro hardware. Joe FitzPatrick was not one of these 17 individual primary sources that included company insiders and government officials, and his direct quote in the story describes a hypothetical example of how a hardware attack might play out, as the story makes clear."

Early Friday, one lawmaker’s office hinted to Codebook that Bloomberg's article might be accurate — but backtracked later in the day. Also on Friday, Sen. Gary Peters (Mich.) sent a letter to Secretary of Defense Jim Mattis asking about armed forces’ knowledge and exposure.

Our thought bubble: It’s possible that well-meaning sources confused malware Apple reportedly found in Supermicro firmware with a hardware-based espionage campaign. The two are not equivalent — the firmware problem was quickly dealt with.

Glass houses disclaimer: Reporters make mistakes. Codebook makes mistakes. Sources are sometimes wrong. And good journalism often necessitates anonymous sources.

Editor's note: This story has been updated with new comment from Bloomberg.

Go deeper

Updated 36 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Health: One startup's plan to deliver at-home COVID tests — Why Americans will be demanding proof of vaccination.
  2. Vaccine: Over 1 million people in the U.S. have received the COVID-19 vaccine — U.S. buys another 100 million doses of Pfizer vaccine.
  3. Politics: The record-breaking stimulus — Trump asks Congress to increase stimulus paymentsPelosi responds: "Let's do it!"
  4. Axios-Ipsos survey: Surviving COVID makes people take it more seriously.
  5. World: New York City will enforce quarantine for U.K. travelers with visits from sheriff's deputies — Antarctica reports first coronavirus casesTaiwan reports first coronavirus case in 8 months.

Trump defies Congress, vetoes $740 billion defense spending bill

Photo: Al Drago via Getty

President Trump defied Congress on Wednesday, vetoing the National Defense Authorization Act (NDAA).

Why it matters: The House and Senate passed the $740 billion defense spending bill with veto-proof majorities, setting up a potential override fight.

U.S. considering closing Iraqi embassy after rocket attack

Iraqi police forces stand guard near the US Embassy in Baghdad on Monday, a day after several rockets were fired into Baghdad's Green Zone. Photo: Ameer Al Mohammedaw/picture alliance via Getty Images

The United States is considering quickly closing its embassy in Baghdad after a series of rocket attacks on Iraq's Green Zone by Iranian-backed militias, according to two sources familiar with the discussions.

Why it matters: The move, among several options being considered, could be a prelude to retaliation against Iran, which President Trump and Secretary of State Mike Pompeo have highlighted as a state sponsor of terror. "Some friendly health advice to Iran: If one American is killed, I will hold Iran responsible. Think it over," the president tweeted Wednesday afternoon.