Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Halliburton’s August 2024 ransomware incident caused service disruptions, involved the theft of data, and was later associated with about $35 million in reported losses. That figure was not identified as a ransom payment. Halliburton said the incident and Gulf of Mexico storms reduced adjusted earnings by $0.02 per share, while management kept its broader full-year expectations for free cash flow and shareholder returns unchanged.
What happened to Halliburton?
Halliburton said it became aware on August 21, 2024, that an unauthorized third party had accessed certain company systems. In an August 22 Form 8-K, the oil-field services company said it activated its cybersecurity response plan, took some systems offline, notified law enforcement, and began restoring affected systems while assessing the incident’s effects.
The filing described portions of business applications supporting operational and corporate functions as affected, but did not provide a detailed list of systems. Halliburton said it was following process-based safety standards for ongoing operations. The public disclosures do not establish that field production equipment or industrial control systems were directly compromised.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →In a September report, Dark Reading reported that Halliburton believed an unauthorized party had accessed and exfiltrated information. On November 7, Halliburton’s third-quarter earnings release described financial effects from the cybersecurity event. On November 11, Dark Reading reported losses of approximately $35 million and identified the ransomware group as RansomHub.
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What data was stolen?
The available public reporting established that data was exfiltrated, but did not identify the information’s type or volume. It did not specify whether employee, customer, supplier, financial, intellectual-property, or operational data was taken, how many records were involved, or whether regulated personal information was affected. The cited reporting also did not establish whether the data was later published or sold.
Calling the event a data breach is reasonable in the broad sense of unauthorized access and data theft. It should not be read as confirmation that personal information was exposed. Ransomware attacks can combine system disruption with data theft and extortion, but the public record cited here does not establish what happened to Halliburton’s stolen data after the intrusion.
Rank #2
- SuperSpeed: A super-fast 64GB USB3.0 USB drive with read speed up to 150MB/S and write speed up to 80MB/S. It has super speed but DOESN'T overheat. Also available in a 128GB capacity. See the A+ comparison chart for details.
- Safety: It comes with A physical write-protect switch and can safely connect to any computer while the switch set to “Read-Only”. In the Protected mode, your data is safe from viruses, malware, data tampering and accidental deletion.
- High Endurance: This flash drive has higher performance and endurance/durability as it adopts A+ MLC memory chip compared with other USB flash drives which use TLC or QLC chips.
- Capacity: This listing is for the 64GB version. A 128GB option is also available. See the A+ comparison chart for details.
- Plug and Play: Simply plug the thumb drive into any USB port and then start data transfer and storage. It is compatible with USB 3.0/3.1 and USB 2.0 ports and works on Windows2000/XP/Vista/7/8/10/11/Server, Mac OS, and Linux. The default format is exFAT file system which allows individual files larger than 4 GB, but you can always re-format to FAT32.
What does the $35 million figure mean?
The approximately $35 million figure was reported as losses associated with the attack. The available sources do not break it down into a complete accounting of lost revenue, response and recovery expenses, or other costs. It should be described as reported losses or estimated financial impact—not as a ransom demand, ransom payment, or a single verified remediation bill.
Halliburton’s third-quarter 2024 earnings release gives related figures, but they measure different things:
Rank #3
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
| Figure | What it describes |
|---|---|
| About $35 million | Losses associated with the attack, as reported by Dark Reading on November 11, 2024. The cited reporting does not provide a full cost breakdown. |
| $0.02 per share | The adjusted-earnings impact Halliburton attributed to lost or delayed revenue from the cybersecurity event and Gulf of Mexico storms together. |
| $116 million pretax charge | A third-quarter charge that included cybersecurity-incident expenses alongside other items; it was not presented as the cost of the attack alone. |
These amounts are not interchangeable and should not be added together. The $0.02-per-share impact combined the cyber event with storms, while the $116 million charge covered multiple items. Neither figure supplies a standalone breakdown of the $35 million estimate.
Why did Halliburton remain optimistic?
Management’s confidence was about the company’s wider financial outlook, not proof that the attack was minor. Halliburton reported third-quarter revenue of $5.7 billion, net income attributable to the company of $571 million, adjusted net income of $641 million, and adjusted diluted earnings per share of $0.73. It said its full-year expectations for free cash flow and cash returns to shareholders remained unchanged.
Rank #4
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
That context helps explain how Halliburton could report a significant incident-related loss while maintaining its overall outlook. It does not mean the event had no cost or consequence: the company disclosed system disruptions, restoration work, and lost or delayed revenue.
Free tools Windows power users keep installed
One-click scans. No signup required.
What the incident shows about business and operational risk
Disruption to business applications can affect scheduling, billing, procurement, logistics, engineering, and support for field work without demonstrating that industrial control systems or production equipment were breached. Taking systems offline can help contain an intrusion, but it can also create friction and delay revenue. Halliburton’s disclosures support the business-application disruption and lost-or-delayed-revenue points; they do not establish a direct OT compromise or a halt to field production.
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
For energy companies, the distinction matters. IT and OT environments have different roles, but business systems often support operational activity. Resilience planning should therefore address system dependencies, safe manual or offline procedures, restoration priorities, and communication with customers and suppliers—not just whether industrial networks are segmented.
Data theft can also create a risk phase beyond technical recovery. In general, stolen information may lead to extortion, publication, fraud, intellectual-property exposure, or third-party claims. Those are possible consequences of data exfiltration, not outcomes established for Halliburton by the cited reports.
What the disclosures do—and do not—establish
Halliburton’s first filing was made under Item 8.01, Other Events, while the company was responding to the intrusion and assessing its effects. A prompt incident disclosure, a later financial-impact update, and a determination of whether an incident is material are related but separate questions. Materiality depends on the circumstances and the incident’s effect on the company as a whole; a $35 million estimate does not automatically settle that question.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteThe initial filing did not name a threat actor. The RansomHub identification appeared in Dark Reading’s November 11 report, so it should be attributed to that later reporting rather than to Halliburton’s original disclosure. Nor does the reported $35 million establish a final cost: the sources cited here do not provide a complete accounting of downstream legal, regulatory, notification, or reputational consequences.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

