Breach taxonomy
Summary
On March 26, 2023, Western Digital identified a network security incident in which an unauthorized third party gained access to a number of company systems. WD proactively disconnected systems and services from the public internet to contain the breach, taking My Cloud service offline (restored April 13) and the online store offline (expected restored ~May 15). An unauthorized party obtained a copy of a database used for the online store containing personal information of online-store customers — names, billing/shipping addresses, email, phone, plus encrypted/hashed/salted passwords and partial credit card numbers. Factories remained operational throughout. Filed under Item 8.01.
Tagging rationale
ThreatUnknown
Filing describes only an 'unauthorized third party' / 'unauthorized party' with no attribution to actor type or motive → UNKNOWN.
MethodsData ExfilSystem Outage
Filing explicitly states 'an unauthorized party obtained a copy of a Western Digital database' — active theft of data → DATA-EXFIL. WD 'proactively disconnected our systems and services from the public Internet' to contain the breach, causing multi-week service outages of My Cloud and the online store → SYSTEM-OUTAGE (containment-driven outage). Initial vector not specified.
AssetsPersonal DataRevenue Process
Filing confirms an unauthorized party 'obtained a copy of a Western Digital database used for our online store' containing customer names, addresses, email, phone, hashed passwords, and partial credit card numbers → PERSONAL-DATA. The online store and My Cloud (revenue-generating consumer services) were disrupted → REVENUE-PROCESS.
EffectsInfo Privacy LossBiz Interruption
Customer PII including hashed passwords and partial credit card data exposed → INFO-PRIVACY-LOSS. My Cloud was offline ~3 weeks (Mar 26 → Apr 13) and the online store ~7 weeks (Mar 26 → ~May 15) → BIZ-INTERRUPTION.
Business continuityPartial
Filing states 'the majority of our impacted systems and services are now operational' and 'factories are and have been operational throughout this incident,' with My Cloud restored April 13 but online store still offline as of the May 5 filing — recovery was achieved unevenly across systems → Partial.
Impact
Large data set exfiltrated (online-store customer database, including hashed passwords and partial credit card numbers); critical consumer cloud service (My Cloud) offline ~3 weeks and online store offline ~7 weeks; significant remediation cost and brand impact for a major consumer storage brand → score 4.
InsuranceNot disclosed
Filing makes no mention of cyber insurance or insurance proceeds → null.
Read the original SEC filing excerpt
Western Digital Provides Update on Network Security Incident — May 5, 2023. On March 26, 2023, we identified a network security incident where an unauthorized third party gained access to a number of the Company’s systems. On April 2, 2023, we disclosed that upon discovery of this incident, we implemented incident response efforts and initiated an investigation with the assistance of leading security industry experts. As a precautionary measure to secure our business operations, the Company proactively disconnected our systems and services from the public Internet. We are progressing through our restoration process and the majority of our impacted systems and services are now operational. Our factories are and have been operational throughout this incident and we are shipping products to meet our customers’ needs. While initially impacted by our proactive measures, as of April 13, 2023, My Cloud service was restored. Account access to Western Digital’s online store also was impacted and is expected to be restored the week of May 15, 2023. In collaboration with outside forensic experts, we confirmed that an unauthorized party obtained a copy of a Western Digital database used for our online store that contained some personal information of our online store customers. This information included customer names, billing and shipping addresses, email addresses and telephone numbers. In addition, the database contained, in encrypted format, hashed and salted passwords and partial credit card numbers.