Cyber Crime
Hewlett Packard Notifies Employees of Data Breach by Russian Hackers
![](https://www.the420.in/wp-content/uploads/2025/02/HPE.webp)
Hewlett Packard Enterprise (HPE) is alerting employees whose personal data was stolen in a May 2023 cyberattack orchestrated by Russian state-sponsored hackers. The breach compromised HPE’s Office 365 email environment, exposing sensitive information.
According to filings with state Attorney General offices in New Hampshire and Massachusetts, HPE began notifying affected individuals in January 2025. At least 16 employees had their driver’s licenses, Social Security numbers, and credit card details stolen.
“HPE’s forensic investigation determined that certain individuals’ personal information may have been subject to unauthorized access,” the company stated in the breach notification letters.
Cozy Bear Behind the Attack
The cyberattack has been attributed to Cozy Bear (also known as Midnight Blizzard, APT29, and Nobelium), a Russian hacking group linked to the Russian Foreign Intelligence Service (SVR). Cozy Bear has a history of high-profile breaches, including the 2020 SolarWinds attack.
Register Now for FutureCrime Summit 2025 – Secure Your Spot Today!
HPE first disclosed the incident in an SEC filing on January 29, 2024, revealing that it was notified on December 12, 2023, about a suspected Russian breach of its cloud-based email system. Hackers exfiltrated data from select employee mailboxes, mainly in cybersecurity, go-to-market, and business segments.
An HPE spokesperson stated that only a “limited group of mailboxes” was accessed, and no other corporate systems were involved. However, further investigation is ongoing.
SharePoint Server Also Breached
The Office 365 attack is believed to be linked to another May 2023 breach, where hackers infiltrated HPE’s SharePoint server and stole files.
Days before HPE’s disclosure, Microsoft also reported that Cozy Bear had infiltrated its corporate email accounts and source code repositories. Microsoft traced the breach to November 2024, when hackers used a password spray attack to access a legacy test account.
HPE’s History of Cyber Breaches
This is not the first time HPE has been targeted:
- 2018: Chinese hackers infiltrated HPE’s network, using it to breach customer devices.
- 2021: The company reported a data breach in its Aruba Central network monitoring platform, exposing device and location data.
- 2024-2025: HPE investigated new security threats after a hacker, using the alias IntelBroker, claimed to have stolen credentials, source code, and sensitive data.
HPE is working with law enforcement and cybersecurity experts to address the breach and has assured that necessary notifications are being made.