Blog Layout

The Cybersecurity Lair™ • February 7, 2024

Latest News | HPE Data Breach Investigation: Navigating Claims and Realities

Russian Hackers and Cyber Intrigues: Unravelling the HPE Security Saga

Hewlett Packard Enterprise (HPE) is investigating a potential data breach following claims made by a threat actor known as IntelBroker, who alleges to have stolen HPE credentials and is offering them for sale on a cybercrime forum. HPE denies evidence of an intrusion and any impact on its products or services. No ransom demand has been reported. 


IntelBroker, previously linked to other cybersecurity incidents, has provided screenshots of claimed HPE credentials. HPE's recent disclosure reveals a separate cyber incursion in May 2023, where Russian hackers, associated with APT29, infiltrated HPE's Microsoft Office 365 email system. 


The breach extended to HPE's cloud infrastructure, with unauthorised access lasting until December. HPE states that a nation-state actor accessed and exfiltrated data, primarily affecting a small percentage of mailboxes related to cybersecurity and business segments. 


This incident follows similar breaches reported by Microsoft. HPE had also faced security breaches in 2018 (linked to APT10) and 2021 (Aruba Central platform compromise). The current data for sale is reported to be from a testing environment, suggesting potentially lower sensitivity compared to operational environments.

Key Points:


  1. HPE is investigating a potential data breach following claims by IntelBroker, who is offering stolen credentials for sale.
  2. HPE denies evidence of an intrusion and reports no impact on products or services, with no ransom demand.
  3. Russian hackers, linked to APT29, breached HPE's Microsoft Office 365 email system in May 2023, exfiltrating data until December.
  4. A nation-state actor accessed and exfiltrated data from a small percentage of HPE mailboxes, impacting cybersecurity and business segments.
  5. IntelBroker has a history of cyber incidents, including breaches of DC Health Link and General Electric Aviation.
  6. HPE previously faced security breaches in 2018 (linked to APT10) and 2021 (Aruba Central platform compromise).
  7. The current data for sale is sourced from a testing environment, potentially less sensitive than operational environments.


Source and further reading.


Gülen, K. (2024, February 7). HPE data breach is under investigation - Dataconomy.
Dataconomy. https://dataconomy.com/2024/02/07/hpe-data-breach-is-under-investigation/

Share by: