Skip to main content
Back to overview
High

HPE Notifies Employees of Data Breach Following Russian Office 365 Hack

Hewlett Packard Enterprise (HPE) began notifying employees on January 29, 2025, about a data breach.

Key points

  • HPE began notifying affected employees on January 29, 2025.
  • Russian state-sponsored hackers (Midnight Blizzard/Cozy Bear) were responsible.
  • Unauthorized access to HPE's Office 365 email environment occurred in May 2023.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

03

Potential impact

Data Exposure

Confidentiality

Published
Jan 29, 2025
Updated
Jul 1, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Hacking activity

Watch internet-facing systems, credential abuse and exploit activity.

  • Source type: possible insider or internal misuse

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

HpeData DisclosureHack Hewlett Packard EnterpriseHPERussianMidnight BlizzardCozy BearOfficeUnauthorized

Quick context

Questions about this signal

What happened in this signal?

Hewlett Packard Enterprise (HPE) began notifying employees on January 29, 2025, about a data breach. Russian state-sponsored hackers (Midnight Blizzard, also known as Cozy Bear) gained unauthorized access to HPE's cloud-based Office 365 email environment in May 2023. The attackers exfiltrated data, including driver's licenses, credit card numbers, and Social Security numbers, from a small percentage of employee mailboxes, particularly those in cybersecurity, go-to-market, and business segments.

When was this signal reported?

Shadow Tier lists Jan 29, 2025 as the signal date.

Which organization is connected to this signal?

Hpe is the organization connected to this public signal.

Explore Hpe
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence