Lyce · Hybrid Watch

hw_d1ecec787bf0e91b

Hacker di APT29 compromettono il sistema di posta elettronica e il server SharePoint di Hewlett Packard Enterprise e rubano file

Il 24 gennaio, Hewlett Packard Enterprise (HPE) ha rivelato che hacker sospettati di legami con la Russia del gruppo APT29 avevano compromesso il suo ambiente di posta elettronica Microsoft Office 365, ottenendo accesso a informazioni appartenenti al team di cybersecurity dell'azienda e ad altri reparti. HPE ha scoperto la violazione il 12 dicembre 2023 e ha stabilito che gli attaccanti avevano ottenuto accesso al suo sistema di posta elettronica basato su cloud già a maggio 2023. Gli hacker hanno anche compromesso il server SharePoint di HPE, dove hanno acceduto ed esfiltrato file.

Evento
2023-05-23
Pubblicazione
2023-05-23T15:53:46Z
Prima osservazione
2026-09-30T16:30:48.138Z
Stato revisione
Non valutato
Paesi
US
Aggiornato
2026-10-02T16:30:09.889Z

Punteggi E/M/R/S

  • EEsistenza0/4 · Non valutato
  • MIntento0/4 · Non valutato
  • RLegame con attore russo0/4 · Non valutato
  • SResponsabilità dello Stato russo0/4 · Non valutato

Fatti

Nessun fatto

Fonti

  1. Ruolo
    discovery_lead
    Data
    2023-05-23T15:53:46Z

    On January 24, Hewlett Packard Enterprise (HPE) revealed that suspected Russian-linked hackers from the APT29 group had compromised its Microsoft Office 365 email environment, gaining access to information belonging to the company’s cybersecurity team and other departments. HPE discovered the breach on December 12, 2023, and determined that the attackers had gained access to its cloud-based email system as early as May 2023. The hackers also compromised HPE’s SharePoint server, where they accessed and exfiltrated files.