Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Greg Hoglund, HBGary’s founder and CEO, said in December 2011 that HBGary, Inc. kept its customers and gained additional business after Anonymous attacked HBGary Federal. That was a claim about the parent company’s business—not evidence that the Federal unit escaped serious consequences. The attack exposed emails, triggered a scandal, and was followed by the resignation of HBGary Federal CEO Aaron Barr.
What happened to HBGary Federal?
The attack followed Barr’s public claim that he had identified people associated with Anonymous and planned to present his findings. Contemporary reporting said Anonymous members broke into HBGary Federal’s website and obtained emails that were later published online. Ellen Messmer’s December 9, 2011 report describes the company’s aftermath; Brian Krebs’s February 7 account and Ars Technica’s February 15 reconstruction cover the lead-up and reported access chain.
HBGary Federal was a separate company created by HBGary to pursue federal-government business. That distinction matters: the headline’s “didn’t ruin us” claim came from Hoglund about HBGary, Inc.’s customer and business outcome, while the breach and its immediate organizational fallout involved the Federal unit.
Why did Hoglund say the attack did not ruin HBGary?
In Messmer’s interview, Hoglund said HBGary did not lose business customers during the year after the attack and “we ended up getting additional business.” He said some customers related to what the company had faced: “They saw us go through things they were experiencing.”
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Those are the CEO’s qualitative statements, not independently audited figures. The interview gives no verified customer-retention percentage or financial accounting of the attack’s impact. Hoglund also said Anonymous never came within “2 to 3 network layers” of HBGary. That, too, is his account—not an independent finding that every parent-company system was untouched.
What were the consequences for HBGary Federal?
The emails’ publication brought reputational and organizational consequences. Messmer reported that some correspondence concerned a proposed effort to marginalize WikiLeaks and that Aaron Barr resigned from HBGary Federal. Krebs reported Hoglund’s contemporaneous concern that publication could expose proprietary material and cost the company millions; that was an estimate at the time, not a verified audited loss.
Accounts differ on the volume of exposed email: Messmer described “tens of thousands,” while Krebs’s report did not provide an exact total. The precise count is not established by those reports.
How did the attackers reportedly get access?
Contemporary technical accounts describe several weaknesses and access steps, rather than a single isolated failure. Ars Technica reported that HBGary Federal’s custom content-management system was vulnerable to SQL injection and used unsalted, non-iterated MD5 password hashes. Attackers reportedly obtained employee login data, cracked weakly protected hashes, and took advantage of password reuse.
Recommended Free Tools
Rank #3
Krebs reported Hoglund’s explanation that attackers obtained credentials for Barr, who had administrator privileges on the email system, expanding access beyond one mailbox. These details describe the reported 2011 incident; they should not be treated as a template for every breach or as a complete account of present-day threats.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What security lesson did Hoglund draw?
Hoglund’s recommendation in the 2011 interview was that “you must use multi-factor authentication in every portal in your enterprise.” The incident also illustrates why authentication is only one part of defense: the reported chain included a vulnerable web application, weak password storage, simple or reused passwords, and powerful account privileges.
Rank #4
- Use multi-factor authentication for accounts and services that support it, especially administrative access.
- Store passwords with a modern, purpose-built password-hashing scheme rather than fast general-purpose hashes.
- Use unique passwords across services so a credential exposed in one place cannot be reused elsewhere.
- Limit administrator privileges to the systems and tasks that require them.
- Patch and test internet-facing applications, including custom-built websites and content-management systems.
These are defensive lessons suggested by the reported weaknesses, not proof that any one control would by itself have prevented the attack.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

