Powered by MOMENTUM MEDIA
cyber daily logo

Powered by MOMENTUMMEDIA

Breaking news and updates daily. Subscribe to our Newsletter

HPE launches investigation into latest IntelBroker breach claims

In what appears to be a repeat incident, Hewlett Packard Enterprise (HPE) has launched an investigation into the latest IntelBroker claims, almost a year after the threat actor claimed a previous attack on the company.

user icon Daniel Croft
Tue, 21 Jan 2025
HPE launches investigation into IntelBroker breach
expand image

The business IT division of major laptop and technology manufacturer Hewlett-Packard (HP) has launched an investigation following claims by a notorious threat actor that the company was breached and data stolen.

Last week, Cyber Daily reported that notorious threat actor IntelBroker, alongside several members of its threat group, CyberN-----s, posted to a popular hacking forum, claiming to have exfiltrated data from Hewlett Packard Enterprise (HPE).

According to the post, the exfiltrated data for sale includes “private Github repositories, Docker builds, SAP Hybris, certificates (private and public keys), product source code: Zerto & iLO” as well as old user personally identifiable information (PII). The threat actor also said that it was selling access to the company’s API, WePay, GitHub and more.

“We’ve been connecting to some of their services for about 2 days now,” wrote IntelBroker.

Now, speaking with Cyber Daily, HPE has revealed that it is aware of the claims and has launched an investigation into the cyber incident.

“HPE became aware on January 16 of claims being made by a group called IntelBroker that it was in possession of information belonging to HPE,” said the company.

“HPE immediately activated our cyber response protocols, disabled related credentials, and launched an investigation to evaluate the validity of the claims.”

While IntelBroker had posted screenshots as proof of the breach, which contained names, email addresses and passwords, HPE said that no customer information has been impacted as far as it’s aware.

“There is no operational impact to our business at this time, nor evidence that customer information is involved,” it said.

This is not the first time IntelBroker has gone after HPE, having listed the company on the same popular hacking forum at the beginning of 2024.

“Today, I am selling the data I have taken from Hewlett Packard Enterprise,” IntelBroker wrote.

“More specifically, the data includes: CI/CD access, System logs, Config Files, Access Tokens, HPE StoreOnce Files (Serial numbers warrant etc) & Access passwords. (Email services are also included).”

HPE launched an investigation into the incident at the time, confirming that it was not a case of ransomware.

“We are aware of the claims and are investigating their veracity,” HPE’s senior director for global communications, Adam R. Bauer, told tech publication BleepingComputer.

“At this time, we have not found evidence of an intrusion, nor any impact to HPE products or services. There has not been an extortion attempt.”

Daniel Croft

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.
You need to be a member to post comments. Become a member for free today!

newsletter
cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.