Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› MSI Signing Keys Leak 2023: How a Ransomware…
Breach analysis Incident: 6 Apr 2023

MSI Signing Keys Leak 2023: How a Ransomware Breach Exposed Firmware and Intel Boot Guard Private Keys

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Category: NHI
Attack route: Not disclosed Identities: Signing key or certificate
On this page

In April 2023, the Money Message ransomware gang claimed it had breached Micro-Star International (MSI), the maker of PCs, laptops and motherboards, and demanded $4 million. MSI confirmed a cyberattack on part of its information systems but did not pay, and the gang began leaking the stolen data. In early May the firmware security company Binarly found private signing keys inside the leak: firmware image signing keys for 57 MSI products and Intel Boot Guard private keys for 116 MSI products. Those keys are what a PC trusts to decide whether firmware is genuine. With them, Binarly warned, an attacker could sign modified firmware that would pass verification. Intel said the Boot Guard keys are generated by manufacturers, not Intel, and that it was investigating. Signing keys cannot be revoked easily on devices already in use, and no reporting we found describes how MSI replaced them. No malicious firmware signed with the leaked keys has been publicly reported.

Key takeaways

  • Money Message claimed the MSI breach on 6 April 2023, saying it had stolen 1.5TB of data, and leaked files after MSI refused its $4 million demand, according to BleepingComputer and SiliconANGLE.
  • Binarly found firmware image signing private keys for 57 MSI products and Intel Boot Guard private keys for 116 MSI products in the leaked data, BleepingComputer and Help Net Security reported in May 2023.
  • Binarly's Alex Matrosov said the leak may affect Boot Guard on MSI devices with 11th, 12th and 13th generation Intel processors, and that one leaked key was also seen on devices from other manufacturers.
  • The theft and leak of the keys are confirmed; abuse of them is not. The risk is that attackers can sign malicious firmware that the hardware will treat as trusted.
  • The identity lesson: signing keys are machine identities for every device that trusts them, so they belong in hardware security modules, never in files that can sit alongside source code.

At a glance

OrganisationsMicro-Star International (MSI); owners of affected MSI devices; Intel, whose Boot Guard feature relied on the leaked OEM keys
WhenBreach claimed 6 April 2023 and confirmed by MSI on 7 April 2023; signing keys found in leaked data and disclosed by Binarly on 5 May 2023
AttackerThe Money Message ransomware and extortion gang, which claimed the attack and leaked the data
Entry pointNot disclosed. MSI confirmed a cyberattack on part of its information systems
Identities abusedMSI firmware image signing private keys (57 products) and Intel Boot Guard OEM private keys (116 products), according to Binarly
ImpactSource code and private signing keys stolen and published; Boot Guard protection weakened on affected devices; no confirmed malicious firmware signed with the keys
CategoryNHI. Incident class: confirmed NHI breach (firmware and Boot Guard signing keys stolen and leaked by a ransomware gang)

What happened

Money Message was a new ransomware group in early 2023. On Thursday 6 April 2023 it listed MSI on its extortion site, SiliconANGLE reported, claiming to have stolen 1.5TB of data, including source code, and demanding $4 million. It set a deadline of 12 April for publishing the files. MSI confirmed the attack the next day: "MSI recently suffered a cyberattack on part of its information systems," it said, adding that there was no significant impact on its financial business. It urged users to obtain firmware and BIOS updates only from its official website. MSI has not published how the attackers got in.

MSI did not pay, and the gang began leaking the data. In the week before 8 May 2023, the leak included MSI firmware source code. Binarly, which specialises in firmware security, analysed it. On 5 May its chief executive, Alex Matrosov, posted: "Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem." BleepingComputer reported that, according to Matrosov, the leaked code contained image signing private keys for 57 MSI products and Intel Boot Guard private keys for 116 MSI products. Binarly's advisory said: "The leaked private parts of the mentioned keys allows a potential attacker to sign the modified firmware" so that it would pass Boot Guard verification.

Intel Boot Guard is a hardware-based check that runs before the operating system and refuses to boot firmware that is not signed by the manufacturer's key. If that key is public, the check cannot tell genuine firmware from a malicious copy signed with it. Intel told BleepingComputer: "Intel is aware of these reports and actively investigating." It added that "Intel BootGuard OEM keys are generated by the system manufacturer, and these are not Intel signing keys." Matrosov said the issue may affect MSI devices with 11th, 12th and 13th generation Intel processors, and Binarly reported, according to Help Net Security, that one leaked key "has been detected on devices from HP, Lenovo, AOPEN, CompuLab, and Star Labs."

Not everyone read the impact the same way. Matrosov himself cautioned, as quoted by Security Affairs: "This is the case, where it's crucial to analyze the impact accurately without overhyping it." The cryptographer Matthew Green asked: "How do you leak an OEM private key for a trusted boot system." The sources we read do not report any malicious firmware signed with the leaked keys, nor a published plan from MSI for replacing them on devices already in use.

Timeline

DateEvent
6 April 2023Money Message lists MSI on its extortion site, claiming 1.5TB of stolen data and demanding $4 million.
7 April 2023MSI confirms a cyberattack on part of its information systems and urges users to download firmware only from its website.
12 April 2023The gang's stated deadline to publish the stolen files if no ransom is paid.
5 May 2023Binarly's Alex Matrosov confirms that an Intel OEM private key is in the leaked data.
8 May 2023BleepingComputer, Help Net Security and Security Affairs report the leaked keys; Intel says it is investigating.

How it happened: the identity attack path

  1. Intrusion into MSI systems. Money Message gained access to part of MSI's information systems. The method has not been disclosed.
  2. Keys stored with code. Private signing keys for firmware images and Intel Boot Guard were present in the data the attackers could reach and copy, alongside firmware source code, according to Binarly's analysis of the leak.
  3. Exfiltration and extortion. The gang took the data and demanded $4 million, threatening to publish it.
  4. Public leak. When MSI refused to pay, the gang published the data, putting the private keys within reach of anyone who downloaded it.
  5. Trust anchor weakened. Devices that trust those keys cannot distinguish MSI's genuine firmware from firmware signed by someone else holding the leaked keys.

Impact

  • Confirmed: MSI confirmed the cyberattack. Binarly confirmed that firmware image signing keys for 57 products and Boot Guard private keys for 116 products were in the leaked data, as reported by BleepingComputer and Help Net Security.
  • Claimed: Money Message claimed to have stolen 1.5TB of data, including source code and a BIOS framework; MSI has not confirmed the volume.
  • Potential: attackers could sign malicious firmware or BIOS updates that pass verification on affected devices, giving persistence below the operating system. Binarly said one key was also seen on other vendors' devices.
  • Not reported: real-world use of the leaked keys to sign malicious firmware.

What this means for NHI governance

A signing key is a machine identity with an unusually wide reach: every device that ships trusting it treats anything it signs as genuine. That is why this leak matters for NHI governance even though no account or token was involved. The keys appear to have been stored somewhere a ransomware gang could copy them along with source code, which suggests they were not held in a hardware security module in non-exportable form.

The lesson from MSI, and from earlier thefts such as NVIDIA's code-signing certificates in 2022, is that signing keys must be generated and used inside hardware, with signing done through a controlled service, logged and approved, and that firmware trust should allow keys to be revoked and replaced. Our Cryptographic Key Management Guide and Device and IoT Identity Guide cover how to do that.

Recommendations

  • Keep signing keys in hardware security modules. Generate them inside the HSM, mark them non-exportable and allow signing only through a controlled service. See our Cryptographic Key Management Guide.
  • Separate signing from source code. Never store private keys in source repositories, build servers or file shares where a data theft would sweep them up with everything else.
  • Require approval and logging for every signature. Treat each signing request as a privileged action, with an owner, a record and alerts for unusual volume. See our Privileged Access Management Guide.
  • Design for key revocation and rotation. Firmware trust chains should support revoking a compromised key and moving devices to a new one. See our Machine Identity, PKI and Certificate Lifecycle Guide.
  • Use separate keys per product line. A single key shared across many products, or across vendors, multiplies the damage of one leak.
  • Install firmware only from the vendor's official channel. For owners of affected devices, this was MSI's own advice, and it limits exposure while trusted keys are in doubt. See our Device and IoT Identity Guide.

Frequently asked questions

What was leaked in the MSI breach?

The Money Message ransomware gang leaked data it stole from MSI in 2023, including firmware source code. Binarly found firmware image signing private keys for 57 MSI products and Intel Boot Guard private keys for 116 MSI products in the leak.

Why do leaked Intel Boot Guard keys matter?

Boot Guard checks that firmware is signed by the manufacturer before a PC starts. With the private key, an attacker could sign malicious firmware that passes that check and runs below the operating system, where it is hard to detect or remove. Intel said the keys are generated by manufacturers, not Intel.

Have the leaked MSI keys been used in attacks?

No real-world use of the leaked keys to sign malicious firmware has been publicly reported in the sources we reviewed. The keys remain a risk for affected devices because signing keys built into hardware trust chains are hard to revoke.

NVIDIA code-signing certificates stolen 2022 · AnyDesk breach 2024 · Microsoft Storm-0558 key breach 2023 · Cryptographic Key Management Guide · Machine Identity, PKI and Certificate Lifecycle Guide

How NHI Mgmt Group can help

Signing keys and certificates are machine identities that customers' devices trust for years. We help organisations find where their signing keys live, move them into hardware with controlled signing services and build revocation into their trust chains. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org