2024 Halliburton — ransomware / unauthorized access; systems offline; confirmed information exfiltration (Aug–Sep)
Data compromised
Corporate and partner/customer-facing operational data—specific categories and volumes not uniformly itemized in first-wave disclosures
Technical writeup
Halliburton publicly acknowledged a cyberattack in late August 2024 that forced containment steps including taking affected systems offline, with follow-on SEC-era reporting characterizing unauthorized access to portions of its environment. Mainstream and trade coverage tied operational disruption (e.g., billing/collections friction) to remediation work and cited eventual acknowledgment that information had been removed from some systems, with public narratives commonly associating the incident with the RansomHub ransomware brand ecosystem. The company later summarized material incident response costs (~$35M) in earnings-oriented reporting.
Root cause
Ransomware-style intrusion and data exfiltration per company disclosures and contemporaneous security press
References
- https://www.reuters.com/technology/cybersecurity/top-us-oilfield-firm-halliburton-hit-by-cyberattack-2024-08-21/
- https://www.reuters.com/technology/cybersecurity/halliburton-reports-unauthorized-exfiltration-information-2024-09-03/
- https://www.bleepingcomputer.com/news/security/us-oil-giant-halliburton-confirms-cyberattack-behind-systems-shutdown/