Lyce · Hybrid Watch

hw_d1ecec787bf0e91b

APT29 hack Hewlett Packard Enterprise email system and sharepoint server, steal files.

On January 24, Hewlett Packard Enterprise (HPE) revealed that suspected Russian-linked hackers from the APT29 group had compromised its Microsoft Office 365 email environment, gaining access to information belonging to the company’s cybersecurity team and other departments. HPE discovered the breach on December 12, 2023, and determined that the attackers had gained access to its cloud-based email system as early as May 2023. The hackers also compromised HPE’s SharePoint server, where they accessed and exfiltrated files.

Occurrence
2023-05-23
Publication
2023-05-23T15:53:46Z
First observed
2026-09-30T16:30:48.138Z
Review status
Not assessed
Countries
US
Updated
2026-10-02T16:30:09.889Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-05-23T15:53:46Z

    On January 24, Hewlett Packard Enterprise (HPE) revealed that suspected Russian-linked hackers from the APT29 group had compromised its Microsoft Office 365 email environment, gaining access to information belonging to the company’s cybersecurity team and other departments. HPE discovered the breach on December 12, 2023, and determined that the attackers had gained access to its cloud-based email system as early as May 2023. The hackers also compromised HPE’s SharePoint server, where they accessed and exfiltrated files.