Hewlett Packard Enterprise (HPE) is investigating a possible new data breachafter a cybercriminal sold data on hacking forums and said it contained HPE credentials and other sensitive information.

The company initially told BleepingComputer that it was investigating the claims, although it had not identified any evidence of a breach or received any ransom notes.
IntelBroker personselling the alleged HPE data, shared screenshots of some of the alleged HPE credentials, but has not provided information about how and where he stole the data.
See also: Blackbaud data breach: FTC calls for security enhancements
“Today, I am selling the data I have received from Hewlett Packard Enterprise,” the hacker states in his post on the hacking forum. “Specifically, the data includes: CI/CD access, System logs, Config Files, Access Tokens, HPE StoreOnce Files (Serial numbers warrant etc) & passwords (including email services).”
Shortly afterwards, a company executive told BleepingComputer that the data being offered for sale was taken from a “test environment.”.
“Based on our investigation to date, the data appears to relate to information contained in a test environment. There is no indication that these allegations relate to any breach of HPE production environments or customer information.“.
IntelBroker is also known for the DC Health Link breach and the exposure of personal data of members and staff of the US House of Representatives . It has also been linked to the Weee! breach and the alleged breach of General Electric Aviation.

Russian hackers breach HPE corporate email accounts
See also: Cloudflare: How an Okta hack led to the company's breach?
HPE's investigation into this breach and leak comes two weeks after the company disclosed a breach of Microsoft Office 365 corporate emails that took place in May 2023. The attack is believed to have been carried out by the Russian hacking group APT29, which is linked to Russia's Foreign Intelligence Service (SVR).
The company said Russian hackers stole SharePoint files and data from its cybersecurity team and other departments. The attackers maintained access to the company's cloud infrastructure until December, when HPE was again notified of a breach of its cloud-based email environment.
“On December 12, 2023, HPE was notified that a suspected nation-state actor had gained unauthorized access to the company’s Office 365 email environment. HPE immediately activated cyber response protocols to initiate an investigation, address the incident, and eliminate the activity,” HPE told BleepingComputer.

What security measures can prevent data theft?
The first and most basic security measure is staff training. Employees need to be aware of the risks and tactics used by hackers, such as phishing, and know how to react to them.
See also: Europcar: Denies data breach allegations
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
It is also important to have a strong virus and malware protection system. This includes regularly updating your security software and installing the latest updates and patches.
Using multi-factor authentication is another measure that can help protect data. This means that the user must provide two or more forms of proof to prove their identity.
Additionally, regularly backing up data is vital. This ensures that even if data is stolen or lost, it can be recovered.
Finally, using encryption can provide additional protection. Encryption converts data into a code that can only be decrypted with a special key.
Source: www.bleepingcomputer.com
