Breach taxonomy
Summary
On March 26, 2023, Western Digital identified a network security incident in which an unauthorized third party gained access to a number of company systems. WD proactively disconnected systems and services from the public internet to contain the breach, taking My Cloud service offline (restored April 13) and the online store offline (expected restored ~May 15). An unauthorized party obtained a copy of a database used for the online store containing personal information of online-store customers — names, billing/shipping addresses, email, phone, plus encrypted/hashed/salted passwords and partial credit card numbers. Factories remained operational throughout. Filed under Item 8.01.
Tagging rationale
ThreatUnknown
Filing describes only an 'unauthorized third party' / 'unauthorized party' with no attribution to actor type or motive → UNKNOWN.