Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HPE said a suspected Russian state-sponsored group accessed and exfiltrated data from its cloud-based email environment beginning in May 2023. The company said it learned of the email intrusion on December 12, 2023, and attributed it to Midnight Blizzard, also known as Cozy Bear. The “six months” description is a rounded summary of those month-level dates, not an exact duration HPE reported.

What happened at HPE?

In a January 24, 2024 filing with the U.S. Securities and Exchange Commission, HPE said it had been notified on December 12, 2023, of unauthorized access to its cloud-based email environment. HPE said a suspected nation-state actor, believed to be Midnight Blizzard, had accessed and exfiltrated data from a small percentage of HPE mailboxes. HPE also said its investigation found the activity was likely related to earlier access involving a limited number of SharePoint files. HPE’s SEC filing described the investigation and scope assessment as ongoing at the time.

HPE identified the actor as the state-sponsored group also known as Cozy Bear. That is HPE’s assessment, not an independently established attribution in the filing. The filing did not specify an exact number or percentage of mailboxes, the number of people whose data was involved, or a total volume of emails.

Why is it described as six months?

HPE said email data access and exfiltration began in May 2023 and that it was notified on December 12. The headline shorthand “six months” comes from those month-level dates; HPE did not state an exact six-month period or give a specific May start date. The company had separately reported earlier SharePoint access and exfiltration dating as early as May.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date What HPE or other reporting said
May 2023 HPE later said access to and exfiltration from its cloud email environment began. It also reported SharePoint activity dating as early as May.
June 2023 HPE said it was notified about the earlier SharePoint activity and investigated with outside cybersecurity experts, taking containment and remediation measures.
December 12, 2023 HPE said it was notified of unauthorized access to its cloud email environment.
January 24, 2024 HPE disclosed the email incident in an SEC filing; its investigation and scope assessment were still ongoing.
FY2024 annual report HPE later said the incident had been investigated and remediated, with no material impact experienced by the company to date.
February 7, 2025 TechCrunch reported that HPE had begun notifying people whose personal information appeared in stolen mailbox data.

What information was accessed?

HPE said the affected mailboxes were associated with cybersecurity, go-to-market, business segments, and other functions. It described the mailbox share as “small” and the number of SharePoint files as “limited,” without publishing exact totals in its initial filing.

In February 2025, TechCrunch reported that notices filed with at least two state attorneys general concerned more than a dozen people at that point. The report said the notices listed Social Security numbers, driver’s license information, and credit card numbers among the data types. HPE did not disclose the total number of individuals affected, according to TechCrunch’s report. The reported notice count should not be read as a complete count of everyone whose information may have been involved.

#1 Best Overall
HPE ProLiant DL360 G10 Gen 10 Server 2.30Ghz 36-Core 128GB RAM + 9.6TB Storage (Renewed)
  • Renewed server with the highest quality standards
  • Ideal for a robust enterprise environment or data center
  • All servers include power cords, and other parts detailed in full product description below
  • Custom configurations available upon request

What did HPE do, and what does “no material impact” mean?

HPE said it activated incident response with outside cybersecurity experts, investigated the activity, contained and remediated it, and eradicated it. Its FY2024 annual report later said the event had been investigated and remediated and that HPE had experienced no material impact to date. That statement concerns impact to the company; it does not establish that no individuals’ personal information was exposed or that no one needed notification.

The later personal-data notifications and the annual report address different questions: one concerns potential effects on individuals, the other HPE’s assessment of material impact to its business. Neither statement supplies a complete public count of affected people or mailboxes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
HPE Proliant DL380 Gen10 8B SFF 2U Server, 2X Intel Xeon Gold 6126 2.6Ghz (24-cores Total), 192GB DDR4 RAM, 8X 1.2TB 2.5” 10K SAS 12Gbps, P408i-a SR 2GB RAID, No Operating System (Renewed)
  • HPE Proliant DL380 Gen10 8-Bay 2.5” Server
  • 2X Intel Xeon Gold 6126 2.6Ghz 12-Core 2.6GHz
  • 192GB DDR4 RAM - 8X 1.2TB 2.5” 10K SAS 12Gbps
  • P408i-a SR Gen10 2GB 12Gbps RAID
  • 4 Port 1GbE NIC - 2x 800W PSU
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was HPE’s incident the same as the Microsoft email compromise?

The available disclosures do not establish that the HPE intrusion and the separate compromise of Microsoft corporate email were one operation. HPE described an intrusion into its own cloud-based email environment and related SharePoint activity. Although later reporting said the HPE systems were hosted by Microsoft, that fact alone does not show that Microsoft caused the HPE incident or that the two incidents shared the same mechanics.

In April 2024, the U.S. Cybersecurity and Infrastructure Security Agency issued a directive concerning Midnight Blizzard’s separate compromise of Microsoft corporate email accounts and required affected federal agencies to analyze exfiltrated correspondence and reset compromised credentials. CISA’s directive documents that federal response; it is not evidence that the Microsoft and HPE incidents were the same intrusion.

Quick Recap

Bestseller No. 1
HPE ProLiant DL360 G10 Gen 10 Server 2.30Ghz 36-Core 128GB RAM + 9.6TB Storage (Renewed)
HPE ProLiant DL360 G10 Gen 10 Server 2.30Ghz 36-Core 128GB RAM + 9.6TB Storage (Renewed)
Renewed server with the highest quality standards; Ideal for a robust enterprise environment or data center
$1,295.00
Bestseller No. 3
HPE ProLiant DL360 Gen10 1U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
HPE ProLiant DL360 Gen10 1U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
HPE ProLiant DL360 Gen10 1U Rack Server with Rail kit for small business or Enterprise; Dual (2) Xeon Gold 6130 16-Core 2.10 GHz, 22MB, Up To 3.70 GHz Turbo
$6,400.00
Bestseller No. 4
HPE ProLiant DL380 Gen10 2U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
HPE ProLiant DL380 Gen10 2U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
HPE ProLiant DL380 Gen10 2U Rack Server with Rail kit for Enterprise; Dual (2) Xeon Gold 6130 16-Core 2.10 GHz, 22MB, Up To 3.70 GHz Turbo
$6,269.80
Best Value
HPE Hewlett Packard Enterprise ProLiant ML30 Gen11 Tower Server w/one Inte Xeon 6315P Processor, 2.8GHz, 4c 1P 1x16GB-U 4LFF-NHP 2x1TB HDD 1x350W PS Smart Choice P83315-005
  • HPE SMART CHOICE PROLIANT MODEL P83315-005: Preconfigured and factory-tested for reliability, this HPE ProLiant ML30 Gen11 Smart Choice model includes 16GB DDR5 memory, 2 x 1TB SATA HDDs, 350W power supply, Intel VROC SATA controller, and embedded 1GbE 4-Port Ethernet adapter—ready for small business deployment
  • POWERFUL PERFORMANCE FOR BUSINESS APPLICATIONS: Built with Intel Xeon 6315P processor (4 cores, 2.8 GHz) and DDR5 ECC memory, this server delivers enterprise-grade performance for workloads such as file sharing, virtualization, database hosting, and collaboration tools in small offices or branch environments
  • FLEXIBLE STORAGE AND EXPANSION OPTIONS: Preconfigured with a 4-bay LFF drive cage and onboard M.2 NVMe SSD support for fast boot. Supports up to 80TB storage capacity and includes four PCIe slots including PCIe Gen5 x16, enabling scalability for data-intensive applications, backup solutions, and growing business needs
  • BUILT-IN SECURITY AND RELIABILITY: Protect your data with HPE iLO Silicon Root of Trust, TPM 2.0 encryption, and firmware malware detection and recovery. Optional redundant 350W power supply ensures uptime for critical workloads like ERP systems, accounting software, and secure file storage
  • SIMPLIFIED MANAGEMENT AND AUTOMATION: Integrated HPE iLO 6 enables remote monitoring, reporting, and automation for quick issue resolution. Compatible with HPE OneView and Compute Ops Management, making it perfect for businesses adopting hybrid cloud strategies and centralized IT management
Rank #4
HPE ProLiant DL380 Gen10 2U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
  • HPE ProLiant DL380 Gen10 2U Rack Server with Rail kit for Enterprise
  • Dual (2) Xeon Gold 6130 16-Core 2.10 GHz, 22MB, Up To 3.70 GHz Turbo
  • Memory: 256GB (8 x 32GB) DDR4 PC4-25600 3200MHz Unbuffered Memory
  • Storage: 7.68TB (4 x 1.92TB) Enterprise 2.5” SATA III 6Gb/s SSDs for Ultra Fast Storage
  • Hard drives and memory upgrades included separately, not installed, installation required.
Rank #3
HPE ProLiant DL360 Gen10 1U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
  • HPE ProLiant DL360 Gen10 1U Rack Server with Rail kit for small business or Enterprise
  • Dual (2) Xeon Gold 6130 16-Core 2.10 GHz, 22MB, Up To 3.70 GHz Turbo
  • Memory: 256GB (8 x 32GB) DDR4 PC4-25600 3200MHz Unbuffered Memory
  • Storage: 7.68TB (4 x 1.92TB) Enterprise 2.5” SATA III 6Gb/s SSDs for Ultra Fast Storage
  • Hard drives and memory upgrades included separately, not installed, installation required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.