UPDATED 17:10 EDT / JANUARY 21 2025

SECURITY

HPE investigating potential breach after hacker claims to steal data

Hewlett Packard Enterprise Co. is investigating a potential breach of its network after a hacker offered to sell data purportedly stolen from the company.

TechCrunch reported the cyberattack today, citing a post on a cybercrime forum dated Jan. 16. In the post, a hacker with the username “IntelBroker” is offering to sell data stolen from HPE’s internal development environments. A year ago, the same hacker sought offers for another dataset purportedly exfiltrated from HPE’s systems.

The latest batch of stolen records reportedly includes some customers’ personally identifiable information. According to the hacker’s forum post, the information is related to HPE product deliveries. It’s unclear how many customers may be affected.

The hacker also claims to have stolen source code related to two HPE software products: Zerto and iLO.

Zerto is a data protection platform that the company obtained in 2021 through a $374 million startup acquisition. It can create backup copies of an organization’s files and recover them after an outage. Zero also provides certain cybersecurity features, including a capability that detects when ransomware attempts to encrypt a company’s data.

The other product affected by the breach, iLO, is an administrative tool that HPE ships with its ProLiant servers. The software can check a server’s firmware before every boot to ensure it wasn’t tampered with by hackers. It also spots technical issues, generates alerts and provides troubleshooting advice for certain types of malfunctions.

Source code repositories are a major target for hackers because they can reveal vulnerabilities in software products. Such vulnerabilities, in turn, can be used to launch cyberattacks. This is particularly true for the source code of software tools that have access to back-end infrastructure such as servers or sensitive data.

Alongside Zerto and iLO code, the HPE breach reportedly affected a number of other internal assets. The hacker behind the cyberattack claims to have stolen Docker builds, or copies of containerized applications, along with access credentials to employee accounts in services such as GitHub and GitLab.

“HPE immediately activated our cyber response protocols, disabled related credentials, and launched an investigation to evaluate the validity of the claims,” the company told TechCrunch in a statement. “There is no operational impact to our business at this time, nor evidence that customer information is involved.”

IntelBroker, the hacker behind the breach, offered to sell another dataset purportedly stolen from HPE last February. That file trove included information related to the company’s StoreOnce series of storage appliances, which are used to store backup files. The hacker also claims to have accessed internal passwords and the CI/CD environment that HPE uses to support its software development efforts. 

According to BleepingComputer, IntelBroker has targeted other enterprise technology companies as well. The list includes Advanced Micro Devices Inc., Cisco Systems Inc. and Nokia Corp. The latter company stated in November that the cyberattack affected a single application operated by a third-party supplier. 

Photo: HPE

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.