HPE investigates IntelBroker claim of stolen source code and repositories
- Organization
- Hewlett Packard Enterprise
- Exploit
- Hacking
- Industry
- Technology
On January 16, 2025 the threat actor known as IntelBroker posted on the BreachForums cybercrime forum offering data it said had been taken from Hewlett Packard Enterprise development environments.
The listing claimed private GitHub repositories, Docker builds, digital certificates including private and public keys, API access, a WePay integration and source code for HPE's Zerto disaster recovery software and Integrated Lights-Out server management platform, along with older personal information tied to customer deliveries. IntelBroker said the access had lasted about two days and published a directory tree and screenshots as evidence.
HPE said it became aware of the claims on January 16, activated its cyber response protocols, disabled credentials it considered at risk and opened an investigation. The company said there had been no operational impact on its business and no evidence that customer information was involved.
Researchers urged caution about the scale of the claim. Arctic Wolf told Cybersecurity Dive that IntelBroker has been known to overstate the significance of data in past breaches. Infosecurity Magazine noted that the actor, previously linked to incidents involving Cisco, General Electric and Europol, was nevertheless not known for entirely fabricated claims.
As of late January 2025 HPE had not confirmed that a breach occurred and had published no findings from its investigation.