Cyber-attack Timeline: Western Digital

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

WD TIMELINE (1) WD SUMMARY

Download Our Educational Cyber-Attack Timeline (Western Digital)

At Cyber Management Alliance, Incident Response and Ransomware Mitigation is our passion. We study and analyse cyber-attacks and ransomware attacks to create informational visual timelines which can be easily read for educational purposes and to enhance cyber resilience.

For the Western Digital Cyber Attack, we have created a visual timeline and an accompanying detailed report.  Download it now. 

Don't forget to read our blog on the Western Digital Cyber Attack.

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed Western Digital attack document and timeline.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the Western Digital Cyber Attack

  • 1. What happened in the Western Digital cyber attack?

    In late March 2023, data-storage company Western Digital (WD) suffered a network security incident in which an unauthorised third party gained access to a number of its systems. WD publicly confirmed the breach on 3 April 2023. The attack forced the company to take systems offline, causing an extended outage of its My Cloud and SanDisk cloud services, and the attackers claimed to have stolen around 10 terabytes of data, including customer information. WD later confirmed that personal data from its online store had been taken. The attackers used a data-theft and extortion approach rather than encrypting files, and the stolen data was subsequently leaked via the ALPHV/BlackCat ransomware group's site.

  • 2. When did the Western Digital cyber attack take place?

    Western Digital identified the network security incident in late March 2023 - reporting points to around 26 March 2023 - and publicly confirmed it in a press release on 3 April 2023. The cloud-service outage ran through early April, with the My Cloud service reported as restored on 13 April 2023. Attacker claims and data leaks continued through April and into early May 2023, and WD confirmed the theft of customer data on 5 May 2023. The company addressed the incident in an SEC quarterly filing around 10 May 2023.

  • 3. Who was behind the Western Digital cyber attack?

    The attackers were never formally identified. One of the hackers spoke to TechCrunch but declined to name themselves or the group, saying they did not go by any name and chose targets 'randomly'. They claimed not to be directly affiliated with the ALPHV ransomware group (also known as BlackCat), but said they knew them to be 'professional' and later used ALPHV's leak site to publish stolen data and pressure WD. No confirmed attribution to a named, established group was established in reporting.

  • 4. How did the attackers breach Western Digital?

    The attacker who spoke to reporters declined to explain exactly how they first broke in or maintained access. They claimed to have exploited vulnerabilities within WD's infrastructure and to have 'spidered' their way to the global administrator of the company's Microsoft Azure tenant - effectively claiming high-level cloud access. To demonstrate their access, the hackers reportedly shared a file signed with Western Digital's code-signing certificate and screenshots from internal systems such as a Box account, a PrivateArk instance and SAP Backoffice. These details came from the attackers' own claims, reported by TechCrunch, rather than from WD.

  • 5. What data was stolen in the Western Digital breach?

    The attackers claimed to have stolen around 10 terabytes of data, including large amounts of customer information, and said they had obtained a complete backup of WD's SAP Backoffice e-commerce system. They also claimed to have taken WD's code-signing certificate, which could in theory be used to digitally sign files and impersonate the company. WD itself later confirmed that an unauthorised party had obtained a copy of a database used for its online store containing customer personal information. The full scope of what was taken was not independently verified, and several figures originate from the attackers' own claims.

  • 6. What customer information was exposed in the Western Digital attack?

    On 5 May 2023, Western Digital confirmed that a database used for its online store had been copied, exposing customer names, billing and shipping addresses, email addresses and telephone numbers. The database also held, in encrypted form, hashed and salted passwords and partial credit card numbers. WD took its online store offline and emailed data-breach notifications to affected customers, while continuing to investigate other data the attackers claimed to have published.

  • 7. Was a ransom demanded in the Western Digital cyber attack?

    Yes - according to TechCrunch, the attackers sought an extortion payment, reportedly demanding a 'minimum 8 figures' (at least tens of millions of dollars) in exchange for not publishing the stolen data. They described wanting a 'one-time payment' to leave WD's network. There is no public confirmation that Western Digital paid any ransom, and when the company did not engage, the stolen data was leaked through the ALPHV/BlackCat site.

  • 8. Were Western Digital's cloud services affected?

    Yes. The incident caused an extended outage across Western Digital's cloud products, including My Cloud, My Cloud Home, My Cloud Home Duo, My Cloud OS5, SanDisk ibi and the SanDisk Ixpand Wireless Charger. As a workaround, WD enabled a 'Local Access' feature so customers could reach files stored locally on their devices over the same network. The company reported that My Cloud was restored on 13 April 2023, and that its factories remained operational throughout the incident.

  • 9. Did the Western Digital attack involve ransomware?

    Not in the traditional sense. The attackers said their goal was to make money but that they deliberately chose not to deploy ransomware to encrypt WD's files. Instead they used a data-theft and extortion model - stealing data and threatening to leak it. When WD did not pay, the stolen material was published via the ALPHV (BlackCat) ransomware group's leak site, even though the original attackers claimed they were not directly part of that group.

  • 10. What was the role of the ALPHV/BlackCat group in the Western Digital breach?

    The ALPHV ransomware group, also known as BlackCat, was used to publish and publicise the stolen data. In late April and early May 2023, researchers reported that ALPHV posted purported screenshots of WD data on its leak site, released around 29 screenshots of emails, documents and video conferences, and even reportedly interrupted a video call of WD's incident response team to taunt them. ALPHV issued further warnings pressing WD to pay. The hackers who carried out the original intrusion said they were not directly affiliated with ALPHV but used its platform for leverage.

  • 11. Was the My Cloud firmware vulnerability (CVE-2022-36327) part of the attack?

    Not as confirmed in reporting. Separately from the breach, Western Digital blocked cloud access for devices running firmware affected by a critical vulnerability tracked as CVE-2022-36327 (CVSS 9.8), a path-traversal flaw that could lead to remote code execution on My Cloud Home, My Cloud Home Duo, SanDisk ibi and My Cloud OS 5 devices. This was disclosed and patched in mid-2023, around the same period, but it was not established as the entry point for the March 2023 network breach.

  • 12. What can organisations learn from the Western Digital cyber attack?

    The Western Digital incident shows how a data-theft extortion attack - without any file encryption - can still cause major disruption, customer-data loss and reputational damage. The key lessons are that cloud identity is critical (the attackers claimed to reach the global administrator of the Azure tenant); that secrets such as code-signing certificates must be tightly protected; that extortion increasingly relies on leak sites rather than ransomware encryption; and that incident response and crisis communications must assume attackers may be watching and leaking in real time. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.

Download The Western Digital Attack detailed document and timeline today. 

download template