Disclosures and evidence

Revision 2 of 2 · Evidence cutoff Nov 15, 2024, 11:59 PM UTC

8 prior statements preserved · 15 statements added. Attributed source statements retain the source’s qualifications.

What the company disclosed

  1. Halliburton Company stated: “On August 21, 2024, Halliburton Company (the “Company”) became aware that an unauthorized third party gained access to certain of its systems.”

Affected organizations and relationships

  1. Halliburton Company stated: “On August 21, 2024, Halliburton Company (the “Company”) became aware that an unauthorized third party gained access to certain of its systems.”

  2. Halliburton Company stated: “The Company is communicating with its customers and other stakeholders. The Company is following its process-based safety standards for ongoing operations under the Halliburton Management System, and is working to identify any effects of the incident.”

Operational impact

  1. Halliburton Company stated: “The incident has caused disruptions and limitation of access to portions of the Company’s business applications supporting aspects of the Company’s operations and corporate functions. The Company believes the unauthorized third party accessed and exfiltrated information from the Company’s systems. The Company is evaluating the nature and scope of the information, and what notifications are required.”

  2. Halliburton Company stated: “The Company continues to provide its products and services to customers globally.”

  3. Halliburton Company stated: “• the outage of the Company’s critical business systems and applications, which impacted aspects of the Company’s operations and corporate functions; and”

Reported data impact

  1. Halliburton Company stated: “The incident has caused disruptions and limitation of access to portions of the Company’s business applications supporting aspects of the Company’s operations and corporate functions. The Company believes the unauthorized third party accessed and exfiltrated information from the Company’s systems. The Company is evaluating the nature and scope of the information, and what notifications are required.”

  2. Halliburton Company stated: “• the nature and scope of information the threat actor appeared to have exfiltrated from the Company’s information technology systems.”

Response

  1. Halliburton Company stated: “When the Company learned of the issue, the Company activated its cybersecurity response plan and launched an investigation internally with the support of external advisors to assess and remediate the unauthorized activity. The Company’s response efforts included proactively taking certain systems offline to help protect them and notifying law enforcement. The Company’s ongoing investigation and response include restoration of its systems and assessment of materiality.”

Recovery updates

  1. Halliburton Company stated: “When the Company learned of the issue, the Company activated its cybersecurity response plan and launched an investigation internally with the support of external advisors to assess and remediate the unauthorized activity. The Company’s response efforts included proactively taking certain systems offline to help protect them and notifying law enforcement. The Company’s ongoing investigation and response include restoration of its systems and assessment of materiality.”

Disclosure timeline

  1. Halliburton Company stated: “Date of Report (Date of earliest event reported): August 21, 2024”

  2. Halliburton Company stated: “| Date: | August 22, 2024 | By: | /s/ Charles E. Geer, Jr.”

  3. Halliburton Company stated: “Date of Report (Date of earliest event reported): August 30, 2024”

  4. Halliburton Company stated: “| Date: | September 3, 2024 | By: | /s/ Charles E. Geer, Jr.”

  5. Halliburton Company stated: “November 15, 2024”

  6. Halliburton Company stated: “Halliburton Company (the “ Company ” or “ Halliburton ”) hereby submits via EDGAR the Company’s response to the comments received from the staff (the “ Staff ”) of the United States Securities and Exchange Commission (the “ Commission ”) set forth in the Staff’s letter to the Company, dated October 17, 2024, received by the Company on November 7, 2024, with respect to the Company’s Form 8-K filed with the Commission via the Commission’s EDGAR system on September 3, 2024 (the “ Item 1.05 Form 8-K ”).”

Disclosure evolution

  1. Halliburton Company stated: “As previously disclosed in a Current Report on Form 8-K, on August 21, 2024, Halliburton Company (the “Company”) became aware that an unauthorized third party gained access to certain of its systems.”

  2. Halliburton Company stated: “Response : The Company filed under Item 1.05 because it concluded that the cybersecurity incident had become material due to the discovery of additional facts after the Company initially disclosed preliminary details of the incident on Form 8-K under Item 8.01 on August 23, 2024. As the Staff is aware, significant cybersecurity incidents are dynamic, and new facts are revealed as the forensic investigation progresses.”

  3. Halliburton Company stated: “In making its determination that a material cybersecurity incident had occurred, the Company was guided by the body of case law on the topic of materiality, as well as the Commission’s pronouncements on the subject. The Company weighed a number of quantitative and qualitative factors, none of which was necessarily material on a stand-alone basis. Instead, the Company’s materiality determination was based on an assessment of the totality of the facts and circumstances that, in the aggregate, led the Company to conclude that the incident had become material to investors. As disclosed in the Item 1.05 Form 8-K, qualitative factors the Company deemed significant included the following:”

Qualifications and uncertainty

  1. Halliburton Company stated: “When the Company learned of the issue, the Company activated its cybersecurity response plan and launched an investigation internally with the support of external advisors to assess and remediate the unauthorized activity. The Company’s response efforts included proactively taking certain systems offline to help protect them and notifying law enforcement. The Company’s ongoing investigation and response include restoration of its systems and assessment of materiality.”

  2. Halliburton Company stated: “The incident has caused disruptions and limitation of access to portions of the Company’s business applications supporting aspects of the Company’s operations and corporate functions. The Company believes the unauthorized third party accessed and exfiltrated information from the Company’s systems. The Company is evaluating the nature and scope of the information, and what notifications are required.”

  3. Halliburton Company stated: “The Company has incurred, and may continue to incur, certain expenses related to its response to this incident. As of the date of this Current Report on Form 8-K, the Company believes that the incident has not had, and is not reasonably likely to have, a material impact on the Company’s financial condition or results of operations. The Company remains subject to various risks due to the incident, including the adequacy of processes during the period of disruption, diversion of management’s attention, potential litigation, changes in customer behavior, and regulatory scrutiny.”

  4. Halliburton Company stated: “The Company respectfully observes that nothing in Item 1.05 or the instructions to Form 8-K requires the Company to describe in a Form 8-K filing the materiality analysis it undertook in determining to make its disclosure. Instead, we believe investors reading Form 8-K understand that when any item of Form 8-K (including Item 1.05) calls for the description of a “material” event, the registrant making responsive disclosure has necessarily concluded that the event is in fact material in compliance with Item 1.05’s materiality assessment factors.”

Disclosure sources and provenance

  • U.S. Securities and Exchange Commission Filed August 23, 2024Report/event date: August 21, 2024Document form: 8-K · Item 8.01SEC HTTPS source · Retrieved Oct 7, 2026, 5:49 PM UTC · Retained Oct 7, 2026, 5:49 PM UTC
  • U.S. Securities and Exchange Commission Filed September 3, 2024Report/event date: August 30, 2024Document form: 8-K · Item 1.05SEC HTTPS source · Retrieved Oct 7, 2026, 5:49 PM UTC · Retained Oct 7, 2026, 5:49 PM UTC
  • U.S. Securities and Exchange Commission Filed November 15, 2024Statement/document date: November 15, 2024Document form: CORRESPSEC HTTPS source · Retrieved Oct 7, 2026, 5:49 PM UTC · Retained Oct 7, 2026, 5:49 PM UTC

Evidence limitations

  • Issuer disclosures establish what was reported, not independent incident verification.