Incident · 8-K Item 8.01
Western Digital reports a network security incident and theft of an online store database
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Western Digital, the storage hardware maker, disclosed on April 3, 2023 that it had identified a network security incident on March 26 in which an unauthorized third party reached a number of its systems. A May 5 update said a copy of its online store customer database had been taken.
First disclosure
The Item 8.01 filing attached an April 2 press release. The company said it had taken systems and services offline and that the unauthorized party had obtained some data.
May 5 update
Western Digital said most systems were back, factories had kept running, and the My Cloud service returned on April 13. It then described the data loss. The database included names, addresses, emails and phone numbers, plus hashed and salted passwords and partial card numbers in encrypted form. The company also said it retained control of its digital certificate infrastructure.
Not stated
Neither release gives the number of customers in the database or names who was responsible.
Sources
- 2023-04-03 · AWestern Digital Corporation, Form 8-K (SEC EDGAR), published April 3, 2023
- 2023-04-02 · AWestern Digital Corporation, press release (Exhibit 99.1, SEC EDGAR), published April 2, 2023
- 2023-05-05 · AWestern Digital Corporation, press release (Exhibit 99.1 to Form 8-K, SEC EDGAR), published May 5, 2023
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.