Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Short answer: Acer was publicly reported as a target of the REvil (also called Sodinokibi) ransomware operation in March 2021. The attackers allegedly demanded $50 million, reportedly in Monero, and claimed to have stolen company documents. Acer acknowledged “abnormal situations” and notifications to authorities but did not publicly confirm the REvil allegation. No reliable public evidence establishes that Acer paid $50 million.
What happened in March 2021?
On March 19, 2021, BleepingComputer reported that REvil had claimed a breach of Acer. The group published images it said came from Acer systems, including financial spreadsheets, bank balances and banking-related communications.
According to the reported attacker conversation, negotiations began on March 14. REvil allegedly set a $50 million demand, offered a 20% discount for rapid payment, and said a deal would include a decryptor, a vulnerability report and deletion of stolen files. These details came from attacker-controlled material and media reporting, not a public forensic report from Acer.
How strong is the evidence?
The public record supports the conclusion that this was a serious ransomware allegation, but it does not give Acer’s own confirmation of every part of the story.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
| Evidence | What it supports | Important limitation |
|---|---|---|
| Acer’s statement | The company had identified abnormal situations, contacted law-enforcement and data-protection authorities, and was investigating. | It did not explicitly confirm REvil, encryption, data theft or the $50 million figure. |
| REvil’s leak-site claim and posted images | The group claimed Acer was compromised and supplied alleged proof. | Attacker material is self-interested and can be incomplete or manipulated; it does not prove that every displayed document was authentic. |
| Malware and threat-intelligence analysis | Independent reporting linked a ransomware sample and related activity to the Acer claim. | Public reporting did not establish a complete forensic reconstruction. |
| Negotiation records reported by journalists | A $50 million demand, discount and proposed concessions were associated with Acer. | A demand is not evidence of payment or total incident cost. |
The careful formulation is that independent reporting and malware analysis linked the incident to REvil, although Acer did not publicly confirm the group’s claim. The Record also contemporaneously corroborated the reported demand and attribution.
What did Acer say?
Acer said it routinely monitored its information-technology systems and had reported recent abnormal situations to relevant law-enforcement and data-protection authorities in multiple countries. The company said it was enhancing its cybersecurity infrastructure and could not provide further details while its investigation was ongoing. That response is consistent with an incident under investigation; it is neither a confirmation of the full REvil narrative nor evidence that the allegation was false.
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
How might the attackers have entered?
Contemporary reporting raised Microsoft Exchange Server as a possible avenue. Threat-intelligence data reportedly showed Acer’s Exchange server being targeted before the incident, as discussed in BleepingComputer’s follow-up.
That is an observed possibility, not a confirmed initial-access finding. The public record does not establish whether an Exchange weakness was exploited, which vulnerability may have been involved, or the complete chain from entry to theft and encryption. It would be inaccurate to state that ProxyLogon or any particular Exchange flaw definitively caused the Acer incident.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
What data was allegedly exposed?
REvil reportedly displayed images of Acer financial documents, bank balances and banking communications, along with other documents it claimed to have taken. The available evidence does not provide a complete inventory of affected systems or data subjects, and it does not establish that all Acer customer data was exposed.
“Stolen data” was part of the extortion claim. In a double-extortion attack, criminals first copy information and may encrypt systems or files, then threaten publication as additional leverage. The screenshots therefore mattered even apart from any disruption: they were intended to show that the attackers had access to sensitive corporate material.
Rank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Did Acer pay the $50 million?
No public confirmation establishes a payment. The public record confirms a reported $50 million demand, not a $50 million transfer. There is also no reliable public figure in the cited reporting for Acer’s operational losses, ransom-related costs or any other total financial impact.
The reported currency was Monero, a cryptocurrency often associated with ransomware negotiations, but that detail came from the ransom reporting rather than an Acer disclosure. A discount or deadline in an attacker conversation indicates negotiation tactics; it does not show that an agreement was reached.
Best Value
- [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Why was the demand so high?
REvil’s alleged demand was extraordinary because Acer is a large multinational hardware manufacturer. Ransomware groups generally set prices according to their estimate of a victim’s ability and willingness to pay. A global company may be viewed as having substantial resources, pressure to restore operations, cyber-insurance considerations and reputational exposure.
The amount could also have served as publicity. A record-setting figure attracts attention, increases pressure on the named victim and advertises the criminal operation to other potential targets. Those are analytical explanations, not documented statements of REvil’s internal decision-making.
Was it the largest ransomware demand?
Within the reporting window on March 19, 2021, the $50 million figure was described as the largest publicly known ransomware demand. That label was temporary. On July 5, 2021, BleepingComputer reported that REvil demanded $70 million in the Kaseya incident: the Kaseya report. Acer’s figure should therefore be described as a historical, date-qualified record—not “the largest ransom ever.”
What the Acer case teaches businesses
The incident illustrates why ransomware resilience cannot depend on a single security product or on having backups that have never been restored. A practical program should include:
- Patch management: prioritize internet-facing services such as email and remote-access systems.
- Strong identity controls: require multifactor authentication, protect privileged accounts and remove unnecessary administrative rights.
- Segmentation: limit how far an intruder can move between user devices, servers, backups and financial systems.
- Resilient backups: keep offline or immutable copies with retention that attackers cannot erase through a compromised administrator account.
- Restore testing: regularly prove that critical systems and data can be recovered within business requirements.
- Detection and logging: use endpoint detection and response, centralized logs and alerting that can reveal unusual access or data movement.
- Prepared response: assign legal, communications, technical, law-enforcement and recovery roles before an incident.
- Ransom decision process: prearrange sanctions screening, insurer notification, evidence preservation and executive approval procedures; do not assume payment guarantees recovery or deletion.
- Data minimization: reduce unnecessary retention of sensitive financial documents and tightly control who can access them.
Do later Acer breaches describe the same incident?
No. Later in 2021, Acer confirmed separate breaches involving an after-sales service system in India and an employee-data system in Taiwan. Acer said the Taiwan incident did not involve customer data and had no material effect on operations or business continuity. Those incidents were reported separately and should not be presented as confirmation of the March REvil ransomware allegation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




