HomeSecurityHewlett Packard Enterprise: Russian hackers breached emails

Hewlett Packard Enterprise: Russian hackers breached emails

Hewlett Packard Enterprise (HPE) revealed today that it suspects Russian hackers Midnight Blizzard of unauthorized access to the email environment Microsoft Office 365 . The hackers' goal was to steal data from the cybersecurity team and other departments.

Hewlett Packard Enterprise HPE emails

Midnight Blizzard hackers, also known as Cozy Bear, APT29, and Nobelium, are a Russian state-run group believed to be part of Russia (SVR). They have been linked to several cyberattacks, including the one on SolarWinds in 2020.

In a new Form 8-K filing with the SEC, HPE says it was notified on December 12 that suspected Russian hackers breached its cloud-based email environment in May 2023.

See also: Microsoft: Russian hackers Nobelium breached its emails

According to the company's filing , the investigation showed that the attackers accessed and stole data from a small percentage of mailboxes belonging to individuals in cybersecurity, go-to-market, business departments, and other functions.

Hewlett Packard Enterprise says it is still investigating the incident, but believes it is related to a previous breach in May 2023, where the company's SharePoint server was accessed.

The company collaborates with law enforcement authorities and external cybersecurity experts.

The data breached by the Russian hackers is limited to the information contained in users' mailboxes.

Although HPE did not provide further details, Microsoft recently reported a security breach by Russian hackers Midnight Blizzard that also included the theft of data from the company's corporate email accounts.

The Microsoft breach began with the compromise of a test tenant account that allowed hackers to gain access to a "small percentage" of Microsoft corporate email accounts for more than a month.

See also: TA866 hackers are back with a new malicious email campaign

Using this access, Midnight Blizzard gained access to corporate email accounts to steal data from Microsoft's senior leadership team and its cybersecurity and legal departments.

HPE told BleepingComputer that they don't know if the incident is related to the Microsoft incident.

Russian hackers Midnight Blizzard
Hewlett Packard Enterprise: Russian hackers breached emails

What are the consequences of a successful email breach?

The first and most immediate consequence of a successful email breach is the violation of the user's privacy . Attackers can gain access to corporate and confidential information, such as private messages, photos, financial data, and more.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Second, a successful email breach can lead to financial loss. Attackers can use the information they obtain to commit fraud, such as identity theft or credit card fraud.

See also: Iranian hackers target researchers with custom malware

A breach can also lead to a loss of professional reputation and trust. If the account belongs to a business or professional, attackers can use the information to damage their image.

Finally, an email breach can lead to legal consequences. If the leaked information includes confidential or sensitive data, the breached business or individual could face legal disputes or penalties.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS