Halliburton has confirmed that its systems were breached, with hackers gaining access to information and leaking it following the cyberattack that occurred last week.

In a recent filing with government regulators on Tuesday, Halliburton said it is “evaluating the nature and extent of the [stolen] information” as well as what data breach notifications it is required to issue
Halliburton announced last week that it had taken some of its systems offline after detecting a cyberattack. The company now says it is “working to determine the impact of the incident” on ongoing oil and fracking operations.
Read also: Halliburton: Is RansomHub ransomware behind the attack?
When contacted Tuesday, Halliburton spokeswoman Amina Rivera would not comment or say whether the company knows what type of data was stolen. “We don’t comment beyond what is in our filing,” Rivera said.
Halliburton says its “ongoing investigation and response” includes restoring its systems and “assessing impacted data.” According to TechCrunch, many of the company’s public systems remain down at the time of writing.
The oil and fracking giant, one of the world's largest energy companies, employs nearly 48,000 people in dozens of countries, according to the latest public filings. Halliburton is closely linked to the explosion that caused the Deepwater Horizon oil rig disaster in the Gulf of Mexico in 2010. Halliburton subsequently agreed to plead guilty and settle charges brought by the U.S. government by paying $1.1 billion.
Halliburton has not provided much information about the current cyberattack. When asked, Halliburton spokesperson Rivera confirmed that the incident is related to ransomware.
See also: North Korean hackers target developers with malicious npm packages
TechCrunch reported the existence of a ransom note allegedly related to the Halliburton incident, which claims that the company's files have been encrypted and stolen. The note attributes the cyberattack to a ransomware gang known as RansomHub .
The dark web RansomHub, which the gang uses to post stolen files and blackmail its victims for ransom, has yet to list Halliburton as one of its victims. It is not uncommon for ransomware gangs and extortionists to reveal the names of their victims when negotiations reach an end.
A RansomHub spokesperson, when reached by TechCrunch, did not comment on the Halliburton attack.
According to a recent US government assessment of the ransomware gang, RansomHub has affected over 210 victims since its inception in February 2024. Furthermore, this gang is linked to the cyberattack that hit the US healthcare technology giant, Change Healthcare.

Halliburton said it will continue to bear costs related to the cyberattack. For 2023, the company reported revenue of $23 billion, while CEO Jeff Miller received total compensation of $19 million during the year.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Read more: Chevrolet's AI chatbot was tricked by hackers and sold a $1 car
Halliburton did not disclose who currently oversees cybersecurity at the company, nor were they available for an interview.
Source: techcrunch
