8-KOther Events

Hewlett Packard Enterprise Co 8-K Report, Cybersecurity Incident (Jan 24, 2024)

Filed January 24, 2024For Securities:HPEHPE-PC

Summary

Hewlett Packard Enterprise Company (HPE) filed an 8-K on January 24, 2024, disclosing a material cybersecurity incident. On December 12, 2023, HPE was alerted to unauthorized access to its cloud-based email environment by a suspected nation-state actor, identified as Midnight Blizzard (Cozy Bear). The investigation revealed that data from a subset of HPE mailboxes, impacting various functions including cybersecurity and go-to-market teams, was accessed and exfiltrated starting in May 2023. While the investigation is ongoing, HPE believes this incident is connected to earlier unauthorized access and exfiltration of SharePoint files reported in June 2023. At this time, HPE states the incident has not materially impacted its operations and is not reasonably likely to materially impact its financial condition or results of operations. The company is cooperating with law enforcement and assessing regulatory notification obligations.

Key Highlights

  • 1HPE experienced a cybersecurity incident involving unauthorized access to its cloud-based email environment by a suspected nation-state actor (Midnight Blizzard/Cozy Bear).
  • 2Data exfiltration from a small percentage of HPE mailboxes occurred starting in May 2023.
  • 3The incident is believed to be related to a previously disclosed SharePoint file exfiltration incident from May 2023.
  • 4HPE has activated its incident response process and is investigating with external cybersecurity experts.
  • 5As of the filing date, the incident has not materially impacted HPE's operations.
  • 6HPE has not determined that the incident is reasonably likely to materially impact its financial condition or results of operations.
  • 7HPE is cooperating with law enforcement and assessing regulatory notification requirements.

Frequently Asked Questions

HPE discovered unauthorized access to its cloud-based email environment by a suspected nation-state actor, believed to be Midnight Blizzard (Cozy Bear). This actor accessed and exfiltrated data from a small percentage of HPE mailboxes.

The unauthorized access was reported on December 12, 2023. However, the investigation indicated that data exfiltration began as early as May 2023.

As of January 24, 2024, HPE stated that the incident has not materially impacted the Company's operations and is not reasonably likely to materially impact its financial condition or results of operations.

HPE has activated its incident response process, engaged external cybersecurity experts for investigation and remediation, is cooperating with law enforcement, and is assessing its regulatory notification obligations.