Russian group APT29 read Hewlett Packard Enterprise email for seven months
- Organization
- Hewlett Packard Enterprise
- Exploit
- Hacking
- Industry
- Technology
Hewlett Packard Enterprise disclosed in a filing with the U.S. Securities and Exchange Commission that became public in late January 2024 that Russian state linked hackers had been reading company email for months. HPE attributed the intrusion to the group tracked as Midnight Blizzard, also known as APT29, Cozy Bear, Nobelium, BlueBravo and Cloaked Ursa, and widely assessed to work for Russia's foreign intelligence service.
According to HPE, the attackers reached its cloud hosted email environment and began exfiltrating data from a small percentage of mailboxes in May 2023. The company said it was notified of that activity on December 12, 2023, more than six months later, and opened an investigation with outside cybersecurity experts.
The affected mailboxes belonged to employees in HPE's cybersecurity, go to market and business segment functions, among others. HPE did not say how many mailboxes were involved or what the messages contained. It said the intrusion was likely related to an earlier incident it was told about in June 2023, in which a limited number of SharePoint files were accessed and exfiltrated.
HPE said the incident had not had a material impact on its operations and was not reasonably likely to materially affect its financial condition. It said it had notified law enforcement and regulatory authorities and that the investigation was continuing. The disclosure came days after Microsoft said the same group had accessed email accounts belonging to its senior staff.