Halliburton took systems offline after August 2024 cyberattack

Organization
Halliburton Company
Exploit
Hacking
Industry
Energy Services

Halliburton, the Houston based oilfield services company, said it became aware on Wednesday, August 21, 2024 that an unauthorized third party had gained access to certain of its systems. The company disclosed the incident to the Securities and Exchange Commission in a Form 8-K filed two days later.

Halliburton activated its cybersecurity response plan, proactively took some systems offline to protect them, engaged external advisers and notified law enforcement. Reporting at the time described disruption at the company's north Houston campus and to some global connectivity, with staff told not to connect to internal networks as a precaution. Customers described being unable to generate invoices or purchase orders while the affected applications were down.

No group had claimed responsibility in the days immediately after the attack, and Halliburton did not name one. News outlets and security researchers subsequently linked the intrusion to the RansomHub ransomware operation, an attribution the company has not confirmed. SecurityWeek noted at the time that the incident had the hallmarks of a ransomware attack, though details remained scarce.

In an updated SEC filing on September 3, 2024, Halliburton confirmed that attackers had accessed and exfiltrated information from its systems, said the incident had caused disruptions and limitation of access to portions of its business applications, and stated that it was evaluating the scope of the affected information and what notifications would be required. The company said it did not expect the incident to have a material effect on its financial condition.

Sources