HEWLETT PACKARD ENTERPRISE COMPANY
bd_cdd41d4da6447050 · schema v1 · pii pii-v1
Full breach record for HEWLETT PACKARD ENTERPRISE COMPANY →2 incidents on fileHPE disclosed an Item 1.05 material cybersecurity incident: on December 12, 2023, HPE was notified that suspected nation-state actor Midnight Blizzard (Cozy Bear) gained unauthorized access to its cloud-based email environment, exfiltrating data from a small percentage of mailboxes beginning May 2023. The incident is believed related to a separately-noticed June 2023 SharePoint exfiltration. HPE engaged external experts, contained and eradicated the activity, and notified law enforcement. No material impact determined as of filing.
J jump to incidentP pin to compareR raw source
Incident timeline
May 1, 2023
Begins
Dec 12, 2023
Discovered
Jan 19, 2024
Scope determined
Jan 24, 2024
Filed
vs. sector median
13 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.