Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

Halliburton’s SEC Filings Detail Its 2024 Cyber Incident

By TheFinanceBase Team4 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Halliburton’s cyber incident occurred in August 2024, not in 2026. The company said an unauthorized third party accessed certain systems, disrupted portions of its business applications and apparently exfiltrated information. Halliburton filed a report classifying the incident as material under SEC Item 1.05 on September 3, 2024; at that time, it said it did not expect a material impact on its financial condition or results of operations.

What happened, and when?

The incident date, the dates Halliburton disclosed it and the date of the material-incident filing are different. The SEC record describes a 2024 event:

Date What Halliburton disclosed
August 21, 2024 Halliburton became aware that an unauthorized third party had accessed certain systems, according to its initial Form 8-K.
August 23, 2024 The company made its initial public disclosure under Item 8.01 of Form 8-K, describing its response, including taking some systems offline and notifying law enforcement.
August 30, 2024 This is the date of the follow-up report describing the incident and Halliburton’s assessment.
September 3, 2024 The follow-up Form 8-K was filed with the SEC under Item 1.05, “Material Cybersecurity Incidents.” The SEC filing index records the filing date.
2025 and 2026 filings Halliburton’s later annual reports and a 2026 quarterly filing referred back to the 2024 event; they did not describe a new August 2026 incident. See the 2024 Form 10-K, 2025 Form 10-K and 2026 quarterly filing.

What Halliburton confirmed—and what remains unknown

In the September 3 report, Halliburton said the incident disrupted and limited access to portions of its business applications. It believed the unauthorized party had accessed and exfiltrated information, and said it was still assessing what information was involved and whether notifications would be required. The company described its response as including an internal investigation with external advisers, removal of some systems from its network, law-enforcement notification, restoration work and communications with customers and other stakeholders. The Form 8-K is the source for these details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Established in the cited filings Not established in those filings
Unauthorized access to certain systems; disruption to portions of business applications; apparent access to and exfiltration of information; response and investigation activity. The attacker’s identity or motive; a ransomware family, extortion demand or payment; the exact information involved; the number of affected people; or whether customer or sensitive personal information was compromised.

That distinction matters when headlines use “data breach.” Halliburton disclosed apparent information exfiltration, but its filing did not identify specific data categories or establish that customer records or personal information were taken. Nor did the cited filings call the event ransomware or attribute it to a country or group.

How extensive was the disruption?

Halliburton’s disclosure referred generally to certain systems and portions of business applications supporting aspects of operations and corporate functions; it did not provide a system-by-system inventory. The company said it continued to provide products and services to customers globally. The filing therefore supports neither a claim that all company systems were compromised nor a claim that global field operations stopped. It also does not provide a customer-by-customer impact assessment.

Why call the incident “material” if Halliburton expected no material financial impact?

These statements concern different questions. Item 1.05 is the SEC filing category Halliburton used after determining that the cybersecurity incident was material for disclosure. Separately, in its September 3 filing, Halliburton said it did not believe the incident had had, or was reasonably likely to have, a material impact on its financial condition or results of operations as of that date. It also said it had incurred, and might continue to incur, response-related expenses.

In a later response to SEC staff, Halliburton explained that its materiality determination reflected the totality of the facts, including outages of critical business systems and applications, effects on parts of operations and corporate functions, and the nature and scope of information that appeared to have been exfiltrated. The SEC response sets out that explanation. Materiality is not synonymous with a quantified earnings loss: operational disruption, possible information exposure and other consequences can be relevant to disclosure even when a material financial hit is not then expected.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did later filings add for investors?

Halliburton’s 2024 Form 10-K described business-application disruptions and limited access, significant costs and management and workforce attention, and potential regulatory, litigation and reputational risks. It also said the incident could affect the company’s business, reputation or consolidated financial condition. Its 2024 annual report provides that later context; the filing does not, in the cited disclosures, provide a specific total dollar loss attributable to the incident.

The 2025 Form 10-K continued to identify the 2024 event as a material cybersecurity incident involving unauthorized access and exfiltration. Halliburton’s 2026 quarterly filing also referred to the prior incident and discussed board and audit-committee oversight of the response and post-incident evaluation. These filings show continuing disclosure of the event’s significance; they do not supply a full forensic account or establish a quantified financial loss.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the filing means for shareholders, customers and suppliers

For investors, the useful questions are not only whether the company disclosed a cyber event, but how it affected continuity, what costs and liabilities may follow, and how the company oversees recovery and controls. Halliburton’s filings identify potential regulatory, litigation and reputational exposure, while leaving the eventual financial effect unquantified in the cited disclosures. They do not establish a specific insurance recovery, customer loss or liability amount.

Customers and suppliers can take the disclosure as confirmation of disruption to portions of Halliburton’s applications, not as proof that their own systems were affected. The public filing does not name affected counterparties or specify whether their data was involved. Organizations assessing their own exposure would need to rely on direct communications and their own operational or contractual records rather than infer impact from the broad SEC description.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.