HPE starts contacting victims of 2023 Russian cyberattack

Closing the cybersecurity skills gap
(Image credit: Shutterstock)

  • HPE begins notifying those affected by the 2023 Midnight Blizzard attack
  • So far, at least a dozen people have received their breach notification letters
  • We don't know exactly how many people were affected

Hewlett Packard Enterprise (HPE) has started sending out breach notification letters to people who were affected by the 2023 data breach, with TechCrunch reporting the company has notified at least a dozen individuals so far, citing a review of breach notices filed with two US state attorney generals.

HPE reported Russian state-sponsored threat actors known as Midnight Blizzard breached its IT systems in 2023 and stole sensitive data from its employees’ email inboxes. In an 8-K submission filed with the US Securities and Exchange Commission (SEC) at the time, the company said the attack started in mid-May 2023, and that it spotted it on December 12.

The investigation uncovered that Midnight Blizzard (also known as Cozy Bear, or Nobelium) had access to “a small percentage” of HPE’s cloud-based email inboxes. Newer reports claim the crooks took Social Security numbers, driver’s license information, and credit card numbers, as well.

No material impact

HPE said the attackers used “a compromised account to access internal HPE email boxes in our Office 365 email environment.” Later, the company clarified the mailboxes belonged to HPE employees in cybersecurity, go-to-market, and business departments.

The exact number of compromised individuals is not known. The company told TechCrunch the data was “limited to information contained in the users’ mailboxes,” suggesting a relatively small number.

That being said, HPE doesn’t believe the attack will have a material impact on the company, or that it will disrupt its operations.

“Upon undertaking such actions, we determined that such activity did not materially impact the Company,” HPE said in the filing. “As of the date of this filing, the incident has not had a material impact on the Company’s operations, and the Company has not determined the incident is reasonably likely to materially impact the Company’s financial condition or results of operations.”

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
HPE
HPE investigating claims that hacker breached developer environments, source code
healthcare
Top US health provider tells 882,000 patients they were hit in August 2023 breach
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
ransomware avast
Engineering giant ENGlobal confirms hackers hit internal data
Insurance
Globe Life data breach may have affected 850,000 more patients than previously thought
Data leak
US utility giant says MOVEit hack exposed stolen data
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound