News: 1706148154

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

HPE joins the 'our executive email was hacked by Russia' club

(2024/01/25)


HPE has become the latest tech giant to admit it has been compromised by Russian operatives.

In a Wednesday [1]regulatory filing [PDF] the enterprise titan revealed that on December 12, 2023, it was "notified that a suspected nation-state actor, believed to be the threat actor Midnight Blizzard, the state-sponsored actor also known as Cozy Bear, had gained unauthorized access to HPE's cloud-based email environment."

HPE "immediately activated our response process to investigate, contain, and remediate the incident, eradicating the activity."

[2]

Eradicating sounds like a good thing! But sadly, this story does not have a happy ending – for three reasons.

[3]

[4]

One is that the investigation found "the threat actor accessed and exfiltrated data … from a small percentage of HPE mailboxes belonging to individuals in our cyber security, go-to-market, business segments, and other functions."

Another is that the exfiltration commenced in May 2023.

[5]

The third is that HPE detected the May incident in June 2023, and "took containment and remediation measures intended to eradicate the activity."

In other words, it looks a lot like those measures didn't work. It's unclear why HPE is confident its efforts to scare Cozy Bear away did the trick this time around.

[6]What Microsoft's latest email breach says about this IT security heavyweight

[7]Australia imposes cyber sanctions on Russian it says ransomwared health insurer

[8]Russia takes $13.5M bite out of Apple over in-app purchases

[9]Sandworm's Kyivstar attack should serve as a reminder of the Kremlin crew's 'global reach'

There's a sliver of good news for HPE investors in the filing's assertion that the most recent incident "has not had a material impact on the Company's operations, and the Company has not determined the incident is reasonably likely to materially impact the Company's financial condition or results of operations."

HPE's share price supports that assertion. It rose a couple of points and stayed solid in after hours trading once news of the hacks emerged.

Which is horrible in its own way, because it suggests investors assume big tech companies are just going to be attacked and have their secrets spilled and don't think that damages their prospects.

[10]

Where that leaves those of us who rely on major tech corporations to provide them with security advice and services is anyone's guess. In the last week alone [11]Microsoft and HPE have both admitted to breaches. ®

Get our [12]Tech Resources



[1] https://otp.tools.investis.com/clients/us/hp_enterprise1/SEC/sec-show.aspx?FilingId=17203043&Cik=0001645590&Type=PDF&hasPdf=1

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbHq-X@9QQDde10zCjykBwAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbHq-X@9QQDde10zCjykBwAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbHq-X@9QQDde10zCjykBwAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbHq-X@9QQDde10zCjykBwAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/01/24/microsoft_latest_breach_cozy_bear/

[7] https://www.theregister.com/2024/01/23/australia_medibank_private_attacker_named/

[8] https://www.theregister.com/2024/01/23/apple_russia_iap_monopoly/

[9] https://www.theregister.com/2024/01/05/sandworm_kyivstar_hack/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbHq-X@9QQDde10zCjykBwAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2024/01/20/chinese_russia_vmware_microsoft/

[12] https://whitepapers.theregister.com/



I. Any body suspended in space will remain in space until made aware of
its situation.
Daffy Duck steps off a cliff, expecting further pastureland. He
loiters in midair, soliloquizing flippantly, until he chances to
look down. At this point, the familiar principle of 32 feet per
second per second takes over.
II. Any body in motion will tend to remain in motion until solid matter
intervenes suddenly.
Whether shot from a cannon or in hot pursuit on foot, cartoon
characters are so absolute in their momentum that only a telephone
pole or an outsize boulder retards their forward motion absolutely.
Sir Isaac Newton called this sudden termination of motion the
stooge's surcease.
III. Any body passing through solid matter will leave a perforation
conforming to its perimeter.
Also called the silhouette of passage, this phenomenon is the
speciality of victims of directed-pressure explosions and of reckless
cowards who are so eager to escape that they exit directly through
the wall of a house, leaving a cookie-cutout-perfect hole. The
threat of skunks or matrimony often catalyzes this reaction.
-- Esquire, "O'Donnell's Laws of Cartoon Motion", June 1980