Desk live·
ForensicPost
Ransomware/Primary source/File 24-0821

The SEC Asked Halliburton to Explain Its Own Disclosure

Halliburton filed under the rule for material cybersecurity incidents, then said the incident was not reasonably likely to be material. The Division of Corporation Finance wrote to ask which it was. The reply is on EDGAR and appears to have gone unreported.

Constructed geometry · not a chart of case data
JurisdictionUSAHouston, Texasthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetHalliburton
ActorRansomHub
D. Kennedy & S. Rosler14 min readConfidence: high5 sources reviewed

On 21 August 2024 Halliburton became aware that an unauthorised third party had reached certain of its systems. It took systems offline, notified law enforcement, and filed a Form 8-K under Item 8.01 — the catch-all "other events" item — two days later. The RansomHub operation listed the company on its leak site shortly afterwards.

On 3 September the company filed again, this time under Item 1.05, the item created by the SEC’s 2023 rule for a material cybersecurity incident. That second filing says the company believes the intruder "accessed and exfiltrated information" from its systems. It also says this:

As of the date of this Current Report on Form 8-K, the Company believes that the incident has not had, and is not reasonably likely to have, a material impact on the Company’s financial condition or results of operations.

Halliburton Company, Form 8-K, Item 1.05, filed 3 September 2024

Read those two facts together and a question forms on its own. The company filed under the item reserved for material incidents, and then said the incident was not materially affecting it.

The Staff Noticed, And Put It In Writing

On 17 October 2024 the SEC’s Division of Corporation Finance sent Halliburton a comment letter. This desk retrieved the company’s reply from EDGAR, which reproduces the staff’s comment in full ahead of the response. The staff asked, in plain terms, why the company had filed under Item 1.05 at all and whether the incident was material.

Please advise us to what extent you considered qualitative factors in your materiality analysis and not just potential impact on financial condition and results of operations.

SEC Division of Corporation Finance, comment letter to Halliburton, 17 October 2024

The letter goes further, citing the rule’s adopting release: the phrase "financial condition and results of operations" is not exclusive, and registrants should weigh customer relationships, competitiveness and reputational harm alongside the money. It closes with a line from the same release — that investors are best served knowing what led management to conclude an incident is material.

The Answer, And Then The Sentence After It

Halliburton replied on 15 November. Its position is that the incident became material as the forensic investigation progressed, on the totality of the circumstances rather than on any single factor. Two qualitative factors are named: the outage of critical business systems and applications, and the nature and scope of the information the threat actor appeared to have taken.

That is a reasonable and fairly candid account. Then comes the sentence that makes this file worth writing.

The Company respectfully observes that nothing in Item 1.05 or the instructions to Form 8-K requires the Company to describe in a Form 8-K filing the materiality analysis it undertook in determining to make its disclosure.

Halliburton Company, response to SEC staff comment, 15 November 2024

The company is almost certainly right. The rule requires disclosure of a material incident; it does not require the registrant to show its working. Filing under Item 1.05 is itself the assertion that the threshold was met, and Halliburton’s reply says as much: investors reading the form understand that the registrant has already concluded the event is material.

What This Costs The Reader

It means the reasoning behind every Item 1.05 filing is invisible by default. Two companies with identical incidents may file differently, and nothing in either document will explain the divergence. The disclosure tells you the conclusion and withholds the method.

The only reason the method is visible here is that a regulator asked in writing and the correspondence is published. That is an accident of the comment-letter process, not a feature of the disclosure regime — and it is the single most useful document this desk has read about how Item 1.05 is actually being applied.

The Number Arrived Separately, On A Different Form

Halliburton’s Form 10-Q for the third quarter, filed 7 November, carries a line item in its impairments and other charges note: cybersecurity incident, $35m. Total charges for the quarter were $116m. Quarterly revenue was $5,697m and net income attributable to the company was $571m.

One incident, four documents, two different questionsSEC EDGAR — filings retrieved and read by this desk
TimeEventEvidence
23 Aug 2024Form 8-K under Item 8.01 — became aware on 21 AugustPrimary document
3 Sep 2024Form 8-K under Item 1.05 — exfiltration confirmed, no material impact statedPrimary document
17 Oct 2024SEC staff asks why Item 1.05 was used and whether the incident is materialReproduced verbatim in the reply
7 Nov 2024Form 10-Q books $35m for the incident against $116m of quarterly chargesPrimary document
15 Nov 2024Company answers, and notes it need not have explained itselfPrimary document

So the $35m is roughly six-tenths of one per cent of the quarter’s revenue and about six per cent of its net income. The September statement that the incident was not reasonably likely to be material to financial condition or results survives the October number without strain. Both are true.

Materiality Scales With The Registrant, And Nothing Else Does

This is the structural point the corpus keeps arriving at from different directions. A $35m loss is immaterial to Halliburton and would end a mid-sized supplier. The disclosure obligation is indexed to the company reporting it, not to the incident, not to the number of people affected, and not to anything downstream.

The consequence is that the disclosure regime is structurally quietest about the largest organisations, which are also the ones whose outages propagate furthest. The corpus filed the same asymmetry at 24-0711 as an arithmetic of who pays; here it appears as a rule about who must speak.

None of which is an accusation against Halliburton. The company filed twice, booked the cost on an audited line rather than burying it, and answered the staff directly. On the evidence in these documents it disclosed more than the rule obliged it to. That is the point: the floor is low enough that exceeding it is unremarkable.

How we reported this

Built on documents retrieved directly from the SEC EDGAR archive and read in full by this desk: the Item 1.05 Form 8-K filed 3 September 2024, the company’s response to SEC staff comments filed 15 November 2024, and the Form 10-Q for the quarter ended 30 September 2024. All quotations are verbatim. The staff’s comment of 17 October 2024 is quoted as reproduced in the company’s response; the desk has not separately retrieved the original letter. Revenue, net income and the $35m charge are as stated in the 10-Q. Attribution of the incident to RansomHub rests on the group’s own leak-site listing and on reporting; the company has not been seen by this desk to confirm it, and the analysis here does not depend on it. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Halliburton Company — Form 8-K, Item 1.05 Material Cybersecurity IncidentU.S. Securities and Exchange Commission (EDGAR)
  2. Halliburton Company — response to SEC staff comments on the Item 1.05 Form 8-KU.S. Securities and Exchange Commission (EDGAR)
  3. Halliburton Company — Form 10-Q, quarter ended 30 September 2024U.S. Securities and Exchange Commission (EDGAR)
  4. Halliburton confirms data stolen in recent cyberattackBleepingComputer
  5. Halliburton cyberattack explained: what happened?TechTarget
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary