Editorial draft v1 · Evidence reader R2 · Evidence cutoff: November 15, 2024

Disclosures covered: August 23 and September 3 filings, and Halliburton's November 15, 2024 response to SEC staff comments.

Halliburton's disclosures describe unauthorized system access, business-application disruption, and a belief that information had been exfiltrated. They also distinguish two assessments that can appear contradictory if read without their scopes: the company did not expect a material financial impact in its September filing, yet later explained that it had concluded the incident was material to investors. The November explanation is Halliburton's account of its judgment, not a regulator's ruling endorsing it. Initial filing · September filing · Company correspondence

Access, shutdowns, and continuing operations

Halliburton said it became aware on August 21, 2024 that an unauthorized third party had accessed certain systems. It activated its response plan, investigated with external advisers, took some systems offline, and notified law enforcement. Restoration and assessment of materiality were ongoing. The initial filing was signed August 22 and filed August 23; those dates are distinct from the August 21 awareness date. Halliburton was communicating with customers and other stakeholders while assessing effects on its operations. Initial filing

The September 3 filing, with an August 30 report header, said the incident had disrupted and limited access to parts of the business applications supporting operations and corporate functions. Halliburton continued to provide products and services globally. Continued service was therefore compatible with disruption; it did not mean every application was available or recovery was complete. The company believed the intruder had accessed and exfiltrated information, but was still assessing its nature, scope, and required notifications. September filing

Two materiality scopes

Halliburton acknowledged incurred and possible future response expenses. As of the September report, however, it believed the incident had not materially affected—and was not reasonably likely to materially affect—its financial condition or results of operations. The filing preserved other risks, including disrupted processes, management distraction, litigation, changing customer behavior, and regulatory scrutiny. The selected disclosure supplies no numerical expense total. September filing

In its November 15 response to SEC staff comments on that filing, Halliburton said additional facts after the August disclosure had led it to conclude the incident had become material. Its assessment considered quantitative and qualitative factors together, rather than requiring any one factor to be material alone. It identified outages of critical systems and applications, and the nature and scope of information the actor appeared to have exfiltrated, as significant qualitative factors. Halliburton described the resulting conclusion as materiality to investors. Company correspondence

The company also argued that Item 1.05 did not require its filing to describe the materiality analysis itself and that investors would understand responsive disclosure under that item to reflect a materiality conclusion. This article reports that argument as the company's position. The retained source is its response letter, not an SEC finding that the analysis or disclosure was sufficient. Company correspondence

What remains unsettled

Editorial interpretation: the sequence is useful because financial-condition language alone does not capture the company's wider assessment of a cybersecurity incident's importance to investors. The later explanation does not erase the earlier disruption or establish a permanent absence of financial risk. These sources do not provide a named actor, intrusion method, defined affected-information categories, population count, quantified incident cost, or completed recovery date. September filing · Company correspondence

Sources

Disclosure history

Article draft version 1 · Evidence reader revision 2 · Evidence cutoff Nov 15, 2024, 11:59 PM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • U.S. Securities and Exchange Commission Filed August 23, 2024Report/event date: August 21, 2024Document form: 8-K · Item 8.01SEC HTTPS source · Retrieved Oct 7, 2026, 5:49 PM UTC · Retained Oct 7, 2026, 5:49 PM UTC
  • U.S. Securities and Exchange Commission Filed September 3, 2024Report/event date: August 30, 2024Document form: 8-K · Item 1.05SEC HTTPS source · Retrieved Oct 7, 2026, 5:49 PM UTC · Retained Oct 7, 2026, 5:49 PM UTC
  • U.S. Securities and Exchange Commission Filed November 15, 2024Statement/document date: November 15, 2024Document form: CORRESPSEC HTTPS source · Retrieved Oct 7, 2026, 5:49 PM UTC · Retained Oct 7, 2026, 5:49 PM UTC