Back to all incidents

Hewlett Packard Enterprise

hpe.com
CONFIRMED

Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.

Observable Status CONFIRMED
Industry / Sector Technology
Incident Classification Nation-State Cloud Intrusion
Attributed Threat Actor Midnight Blizzard (APT29)
Affected Population Scope Under Audit
First Seen 2024-01-19
Last Updated 2024-01-24
Cybersecurity Team Mailboxes Executive Communications Legal & Business Unit Records
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

91% CONFIDENCE
1. Primary Authority CONFIRMED BY REGULATOR Base weight: 65%
2. Evidence Specificity +19% Statutory Filing Verified
3. Corroboration Curve +7% 2 independent domains
4. Timeline & Staleness +0% 2 milestones logged
Corroborated Source Domains:
hpe.com sec.gov
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
U.S. Securities and Exchange Commission (SEC)

Form 8-K Item 1.05 (Material Cybersecurity Incidents)

CONFIRMED BY REGULATOR
Docket / Accession ID 0001645590-24-000003
Statutory Filing Date 2024-01-19
Disclosed Impact Scope Under Audit
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Item 1.05 Material Cybersecurity Incident disclosure filed by Hewlett Packard Enterprise Company reporting nation-state actor Midnight Blizzard accessing corporate cloud email environment and exfiltrating messages.

View Official Regulatory Filing Document https://www.sec.gov/Archives/edgar/data/1645590/000164559024000003/hpe-20240119.htm

Technical Forensic Briefing

Incident Overview

Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.

Compromised Assets & Data Scope

  • Primary Data Classes: Cybersecurity Team Mailboxes, Executive Communications, Legal & Business Unit Records.

Statutory Disclosures & Compliance

  • Statutory filing submitted to SEC (Form 8-K (Item 1.05)) under accession 0001645590-24-000003.

Milestone Timeline (2 events logged)

2024-01-19 16:30 UTC
CONFIRMED BY TARGET

HPE notified that nation-state actor Midnight Blizzard gained unauthorized access to Office 365 cloud email environment.

2024-01-24 17:00 UTC
CONFIRMED BY REGULATOR

HPE files Form 8-K Item 1.05 disclosing data exfiltration from cybersecurity, legal, and operational team mailboxes dating back to May 2023.

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub