Article Details

Scrape Timestamp (UTC): 2025-01-21 13:25:16.096

Source: https://www.theregister.com/2025/01/21/hpe_intelbroker_claims/

Original Article Text

Click to Toggle View

HPE probes IntelBroker's bold data theft boasts. Incident response protocols engaged following claims of source code burglary. Hewlett Packard Enterprise (HPE) is probing assertions made by prolific Big Tech intruder IntelBroker that they broke into the US corporation's systems and accessed source code, among other things. In a statement sent to The Register, HPE confirmed it was informed of the cyber criminal's claims late last week: "HPE became aware on January 16 of claims being made by a group called IntelBroker that it was in possession of information belonging to HPE. HPE immediately activated our cyber response protocols, disabled related credentials, and launched an investigation to evaluate the validity of the claims. "There is no operational impact to our business at this time, nor evidence that customer information is involved." The attacker is selling the allegedly stolen data on a cybercrime forum, claiming to offer access to HPE source code taken from private GitHub repos, Docker builds, and SAP Hybris. IntelBroker also claims that personally identifiable information (PII) of users is up for grabs, taken from old delivery records, and boasts they will sell access to APIs, WePay, self-hosted GitHub repos, and more. The spokesperson did not respond to specific questions regarding the nature of the potentially affected data types. As is the case with all claims made by career criminals, take them with a pinch of salt. The truth is often stretched, if there is any at all. However, in the case of IntelBroker, the criminal fairly often makes good on their promises, albeit with some facts exaggerated here and there. Europol, for example, confirmed its Platform for Experts was involved in an incident claimed by IntelBroker in May 2024. This followed claims that data was stolen from the Pentagon and other security agencies via consulting biz Acuity a month earlier. Acuity confirmed it was attacked but said no sensitive data was involved. Days after the Pentagon claims, IntelBroker allegedly went after Home Depot, which later confirmed its employees' personal data was accessed. Other alleged attacks include those on AMD, Apple, Korea's Ministry of Defense, and the US Army. IntelBroker is an admin of the cybercrime forum to which HPE's alleged data was posted and is also a known member of the Valhalla doxxing gang, which has associations with some of the more grisly types of cybercriminals out there. Cybersecurity outfit Kela published an investigation into IntelBroker earlier this month, suggesting the group may also be part of the AgainstTheWest cybercrime group, which is known for attacking Chinese targets. Kela also noted the attacker's reliance on a logless VPN service, which suggested their possible locations being in Serbia, Amsterdam, or Virginia, as well as their sophisticated tactics. "IntelBroker represents the sophistication of today's cybercriminals – blending technical skill with strategic anonymity," the report reads.

Daily Brief Summary

CYBERCRIME // HPE Investigates IntelBroker's Claims of Source Code Theft

Hewlett Packard Enterprise (HPE) is investigating claims by IntelBroker about unauthorized access to HPE systems and the theft of source code.

IntelBroker, known for past cybercriminal activities, alleged possession of HPE data, including source code from GitHub, Docker builds, and SAP Hybris.

HPE activated its incident response protocols immediately after being notified of the potential breach on January 16, taking measures such as disabling related credentials.

The company confirmed no current operational impact or evidence indicating customer information was compromised.

The stolen data is reportedly being offered for sale on a cybercrime forum, suggesting that personally identifiable information (PII) from old records is also available.

Europol and previous incidents suggest IntelBroker typically fulfills some of their threats, prompting heightened caution and verification efforts.

IntelBroker is also linked to the notorious Valhalla doxxing gang and potentially the AgainstTheWest group, a detail uncovered by cybersecurity firm Kela.