Skip to content
cisonews.net

Incident · 8-K Item 8.01

Western Digital reports a network security incident and theft of an online store database

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Western Digital, the storage hardware maker, disclosed on April 3, 2023 that it had identified a network security incident on March 26 in which an unauthorized third party reached a number of its systems. A May 5 update said a copy of its online store customer database had been taken.

First disclosure

The Item 8.01 filing attached an April 2 press release. The company said it had taken systems and services offline and that the unauthorized party had obtained some data.

May 5 update

Western Digital said most systems were back, factories had kept running, and the My Cloud service returned on April 13. It then described the data loss. The database included names, addresses, emails and phone numbers, plus hashed and salted passwords and partial card numbers in encrypted form. The company also said it retained control of its digital certificate infrastructure.

Not stated

Neither release gives the number of customers in the database or names who was responsible.

Sources

  1. 2023-04-03 · AWestern Digital Corporation, Form 8-K (SEC EDGAR), published April 3, 2023
  2. 2023-04-02 · AWestern Digital Corporation, press release (Exhibit 99.1, SEC EDGAR), published April 2, 2023
  3. 2023-05-05 · AWestern Digital Corporation, press release (Exhibit 99.1 to Form 8-K, SEC EDGAR), published May 5, 2023

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.