2024 HPE — Midnight Blizzard / Cozy Bear cloud email and SharePoint exfiltration; workforce PII notices
Data compromised
Employee-oriented PII per 2025 notification summaries—categories vary by person
Technical writeup
Hewlett Packard Enterprise filed an SEC Form 8-K describing unauthorized access to a cloud-hosted corporate email environment beginning in May 2023 and attributed to a suspected nation-state actor since publicly associated with Midnight Blizzard (Cozy Bear), with follow-on theft framed around SharePoint-sourced data. Early 2025 regulatory and press coverage documented workforce-focused breach letters citing driver's license, government ID, financial-account, and Social Security–class fields for employee populations rather than a consumer tally normalized in open sources.
Root cause
Suspected nation-state actor access to cloud identity and collaboration plane (Microsoft 365 / SharePoint narrative in vendor and press)