On 21 August 2024 Halliburton became aware that an unauthorised third party had reached certain of its systems. It took systems offline, notified law enforcement, and filed a Form 8-K under Item 8.01 — the catch-all "other events" item — two days later. The RansomHub operation listed the company on its leak site shortly afterwards.
On 3 September the company filed again, this time under Item 1.05, the item created by the SEC’s 2023 rule for a material cybersecurity incident. That second filing says the company believes the intruder "accessed and exfiltrated information" from its systems. It also says this:
As of the date of this Current Report on Form 8-K, the Company believes that the incident has not had, and is not reasonably likely to have, a material impact on the Company’s financial condition or results of operations.
Halliburton Company, Form 8-K, Item 1.05, filed 3 September 2024
Read those two facts together and a question forms on its own. The company filed under the item reserved for material incidents, and then said the incident was not materially affecting it.
The Staff Noticed, And Put It In Writing
On 17 October 2024 the SEC’s Division of Corporation Finance sent Halliburton a comment letter. This desk retrieved the company’s reply from EDGAR, which reproduces the staff’s comment in full ahead of the response. The staff asked, in plain terms, why the company had filed under Item 1.05 at all and whether the incident was material.
Please advise us to what extent you considered qualitative factors in your materiality analysis and not just potential impact on financial condition and results of operations.
SEC Division of Corporation Finance, comment letter to Halliburton, 17 October 2024
The letter goes further, citing the rule’s adopting release: the phrase "financial condition and results of operations" is not exclusive, and registrants should weigh customer relationships, competitiveness and reputational harm alongside the money. It closes with a line from the same release — that investors are best served knowing what led management to conclude an incident is material.
The Answer, And Then The Sentence After It
Halliburton replied on 15 November. Its position is that the incident became material as the forensic investigation progressed, on the totality of the circumstances rather than on any single factor. Two qualitative factors are named: the outage of critical business systems and applications, and the nature and scope of the information the threat actor appeared to have taken.
That is a reasonable and fairly candid account. Then comes the sentence that makes this file worth writing.
The Company respectfully observes that nothing in Item 1.05 or the instructions to Form 8-K requires the Company to describe in a Form 8-K filing the materiality analysis it undertook in determining to make its disclosure.
Halliburton Company, response to SEC staff comment, 15 November 2024
The company is almost certainly right. The rule requires disclosure of a material incident; it does not require the registrant to show its working. Filing under Item 1.05 is itself the assertion that the threshold was met, and Halliburton’s reply says as much: investors reading the form understand that the registrant has already concluded the event is material.
What This Costs The Reader
It means the reasoning behind every Item 1.05 filing is invisible by default. Two companies with identical incidents may file differently, and nothing in either document will explain the divergence. The disclosure tells you the conclusion and withholds the method.
The only reason the method is visible here is that a regulator asked in writing and the correspondence is published. That is an accident of the comment-letter process, not a feature of the disclosure regime — and it is the single most useful document this desk has read about how Item 1.05 is actually being applied.
The Number Arrived Separately, On A Different Form
Halliburton’s Form 10-Q for the third quarter, filed 7 November, carries a line item in its impairments and other charges note: cybersecurity incident, $35m. Total charges for the quarter were $116m. Quarterly revenue was $5,697m and net income attributable to the company was $571m.
So the $35m is roughly six-tenths of one per cent of the quarter’s revenue and about six per cent of its net income. The September statement that the incident was not reasonably likely to be material to financial condition or results survives the October number without strain. Both are true.
Materiality Scales With The Registrant, And Nothing Else Does
This is the structural point the corpus keeps arriving at from different directions. A $35m loss is immaterial to Halliburton and would end a mid-sized supplier. The disclosure obligation is indexed to the company reporting it, not to the incident, not to the number of people affected, and not to anything downstream.
The consequence is that the disclosure regime is structurally quietest about the largest organisations, which are also the ones whose outages propagate furthest. The corpus filed the same asymmetry at 24-0711 as an arithmetic of who pays; here it appears as a rule about who must speak.
None of which is an accusation against Halliburton. The company filed twice, booked the cost on an audited line rather than burying it, and answered the staff directly. On the evidence in these documents it disclosed more than the rule obliged it to. That is the point: the floor is low enough that exceeding it is unremarkable.
Built on documents retrieved directly from the SEC EDGAR archive and read in full by this desk: the Item 1.05 Form 8-K filed 3 September 2024, the company’s response to SEC staff comments filed 15 November 2024, and the Form 10-Q for the quarter ended 30 September 2024. All quotations are verbatim. The staff’s comment of 17 October 2024 is quoted as reproduced in the company’s response; the desk has not separately retrieved the original letter. Revenue, net income and the $35m charge are as stated in the 10-Q. Attribution of the incident to RansomHub rests on the group’s own leak-site listing and on reporting; the company has not been seen by this desk to confirm it, and the analysis here does not depend on it. Graded high. Corrections: corrections@forensicpost.com.
- Halliburton Company — Form 8-K, Item 1.05 Material Cybersecurity IncidentU.S. Securities and Exchange Commission (EDGAR)
- Halliburton Company — response to SEC staff comments on the Item 1.05 Form 8-KU.S. Securities and Exchange Commission (EDGAR)
- Halliburton Company — Form 10-Q, quarter ended 30 September 2024U.S. Securities and Exchange Commission (EDGAR)
- Halliburton confirms data stolen in recent cyberattackBleepingComputer
- Halliburton cyberattack explained: what happened?TechTarget