ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

We collaborate and engineer solutions to maximize asset value for our customers. Founded in 1919, Halliburton is one of the world's largest providers of products and services to the energy industry. With more than 45,000 employees, representing 130 nationalities in more than 80 countries, the company helps its customers maximize value throughout the lifecycle of the reservoir – from locating hydrocarbons and managing geological data, to drilling and formation evaluation, well construction and completion, and optimizing production throughout the life of the asset.

Halliburton A.I CyberSecurity Scoring

Halliburton

Company Details

Linkedin ID:

halliburton

Employees number:

58,792

Number of followers:

2,732,816

NAICS:

211

Industry Type:

Oil and Gas

Homepage:

halliburton.com

IP Addresses:

106

Company ID:

HAL_1763806

Scan Status:

Completed

AI scoreHalliburton Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/halliburton.jpeg
Halliburton Oil and Gas
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreHalliburton Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/halliburton.jpeg
Halliburton Oil and Gas
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Halliburton Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
HalliburtonCyber Attack10058/2024
Rankiteo Explanation :
Attack threatening the organization’s existence

Description: Halliburton, a major energy services company, suffered a cyberattack on **August 21, 2024**, leading to operational disruptions after an unauthorized breach of its systems. The incident, disclosed in an **SEC 8-K filing**, prompted the company to isolate affected systems, initiate internal and external investigations, and engage law enforcement. While the full scope and specifics of the attack remain undisclosed, Halliburton is collaborating with cybersecurity experts to restore systems and mitigate risks.The attack underscores the escalating cyber threats targeting **critical infrastructure**, particularly in the **energy sector**, where operational downtime can have cascading effects on supply chains, financial stability, and national security. Given Halliburton’s role in oilfield services, the breach could disrupt energy production, logistics, or proprietary technologies, potentially affecting global markets. The incident also highlights vulnerabilities in industrial control systems (ICS) and the urgent need for fortified defenses against sophisticated cyber threats in high-stakes sectors.

Halliburton
Cyber Attack
Severity: 100
Impact: 5
Seen: 8/2024
Blog:
Rankiteo Explanation
Attack threatening the organization’s existence

Description: Halliburton, a major energy services company, suffered a cyberattack on **August 21, 2024**, leading to operational disruptions after an unauthorized breach of its systems. The incident, disclosed in an **SEC 8-K filing**, prompted the company to isolate affected systems, initiate internal and external investigations, and engage law enforcement. While the full scope and specifics of the attack remain undisclosed, Halliburton is collaborating with cybersecurity experts to restore systems and mitigate risks.The attack underscores the escalating cyber threats targeting **critical infrastructure**, particularly in the **energy sector**, where operational downtime can have cascading effects on supply chains, financial stability, and national security. Given Halliburton’s role in oilfield services, the breach could disrupt energy production, logistics, or proprietary technologies, potentially affecting global markets. The incident also highlights vulnerabilities in industrial control systems (ICS) and the urgent need for fortified defenses against sophisticated cyber threats in high-stakes sectors.

Ailogo

Halliburton Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Halliburton

Incidents vs Oil and Gas Industry Average (This Year)

No incidents recorded for Halliburton in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Halliburton in 2025.

Incident Types Halliburton vs Oil and Gas Industry Avg (This Year)

No incidents recorded for Halliburton in 2025.

Incident History — Halliburton (X = Date, Y = Severity)

Halliburton cyber incidents detection timeline including parent company and subsidiaries

Halliburton Company Subsidiaries

SubsidiaryImage

We collaborate and engineer solutions to maximize asset value for our customers. Founded in 1919, Halliburton is one of the world's largest providers of products and services to the energy industry. With more than 45,000 employees, representing 130 nationalities in more than 80 countries, the company helps its customers maximize value throughout the lifecycle of the reservoir – from locating hydrocarbons and managing geological data, to drilling and formation evaluation, well construction and completion, and optimizing production throughout the life of the asset.

Loading...
similarCompanies

Halliburton Similar Companies

Baker Hughes

Baker Hughes (NASDAQ: BKR) is an energy technology company that provides solutions for energy and industrial customers worldwide. Built on a century of experience and conducting business in over 120 countries, our innovative technologies and services are taking energy forward – making it safer, clea

Equinor

We're Equinor, an international energy company with a proud history. Formerly Statoil, we are 20,000 committed colleagues developing oil, gas, wind and solar energy in more than 30 countries worldwide. We’re the largest operator in Norway, among the world’s largest offshore operators, and a growing

Nosso propósito é prover energia que assegure prosperidade de forma ética, justa, segura e competitiva. Queremos ser a melhor empresa diversificada e integrada de energia na geração de valor, construindo um mundo mais sustentável, conciliando o foco em óleo e gás com a diversificação em negócios de

PETRONAS

Petroliam Nasional Berhad (PETRONAS) is a leading global energy company committed to powering society’s progress in a responsible and sustainable manner. With close to 50,000 employees and a global reach spanning over 100 countries, we are ranked among the world’s largest corporations by revenue in

Oxy is an international energy company with assets primarily in the United States, the Middle East and North Africa. We are one of the largest oil producers in the U.S., including a leading producer in the Permian and DJ basins, and offshore Gulf of Mexico. Our midstream and marketing segment provid

ExxonMobil

The need for energy is universal. That's why ExxonMobil scientists and engineers are pioneering new research and pursuing new technologies to reduce emissions while creating more efficient fuels. We're committed to responsibly meeting the world's energy needs. We aim to achieve #netzero emissions

Reliance Industries Limited

Our motto “Growth is Life” aptly captures the ever-evolving spirit of Reliance. Our activities span hydrocarbon exploration and production, petroleum refining and marketing, petrochemicals, retail, and telecommunications. In each of these areas, we are committed to innovation-led, exponential growth

En YPF, tenemos un Plan 4x4 para convertirnos en una compañía de clase mundial y lograr transformarnos en grandes exportadores de hidrocarburos. Nuestros cuatro pilares son: la aceleración de la producción de petróleo en Vaca Muerta, el activo más importante que tiene nuestro país; la disciplina f

McDermott International, Ltd

McDermott is a premier provider of engineering and construction solutions to the energy industry. Our customers trust our technology-driven approach—engineered to responsibly harness and transform global energy resources into the products the world needs for now and what’s next. From concept to co

newsone

Halliburton CyberSecurity News

December 03, 2024 08:00 AM
ENGlobal IT systems impacted by ransomware attack

The attack marks at least the third disruptive cyberattack impacting energy sector providers based in Texas since August.

November 22, 2024 08:00 AM
Oil Giant Halliburton Lost $35 Million Due to the August 2024 RansomHub Ransomware Data Breach

Halliburton says that the data breach loss stemming from the August 2024 ransomware attack that disrupted operations amounts to $35 million.

November 11, 2024 09:58 PM
Halliburton Optimistic Amid $35M Data Breach Loss

Halliburton, a multinational corporation known for its oil and gas products and services, reported that its losses after a ransomware attack in August have...

November 11, 2024 08:00 AM
Cyberattack Cost Oil Giant Halliburton $35 Million

In its latest financial report, Halliburton said the recent cybersecurity incident has so far cost the company $35 million.

November 11, 2024 08:00 AM
August Halliburton hack led to $35m loss, company admits

The breach disrupted Halliburton's systems and led to data being exfiltrated - though precisely what information was lost remains unknown.

November 11, 2024 08:00 AM
Newpark Resources discloses October ransomware attack

The Newpark Resources attack took place about two months after a cyberattack against oilfield services giant Halliburton, which also disclosed the incident in...

November 11, 2024 08:00 AM
Newpark Resources hit by ransomware; activates cybersecurity response

Texas-based oilfield services supplier Newpark Resources detected a ransomware attack by an unauthorized party accessing internal systems.

November 11, 2024 08:00 AM
Halliburton reports $35 million loss after ransomware attack

Halliburton has revealed that an August ransomware attack has led to $35 million in losses after the breach caused the company to shut down IT systems and...

November 11, 2024 08:00 AM
Halliburton Acknowledges Cost of Hacking Incident

'We experienced a $0.02 per share impact to our adjusted earnings from lost or delayed revenue due to the August cybersecurity event and...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Halliburton CyberSecurity History Information

Official Website of Halliburton

The official website of Halliburton is https://www.halliburton.com.

Halliburton’s AI-Generated Cybersecurity Score

According to Rankiteo, Halliburton’s AI-generated cybersecurity score is 790, reflecting their Fair security posture.

How many security badges does Halliburton’ have ?

According to Rankiteo, Halliburton currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Halliburton have SOC 2 Type 1 certification ?

According to Rankiteo, Halliburton is not certified under SOC 2 Type 1.

Does Halliburton have SOC 2 Type 2 certification ?

According to Rankiteo, Halliburton does not hold a SOC 2 Type 2 certification.

Does Halliburton comply with GDPR ?

According to Rankiteo, Halliburton is not listed as GDPR compliant.

Does Halliburton have PCI DSS certification ?

According to Rankiteo, Halliburton does not currently maintain PCI DSS compliance.

Does Halliburton comply with HIPAA ?

According to Rankiteo, Halliburton is not compliant with HIPAA regulations.

Does Halliburton have ISO 27001 certification ?

According to Rankiteo,Halliburton is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Halliburton

Halliburton operates primarily in the Oil and Gas industry.

Number of Employees at Halliburton

Halliburton employs approximately 58,792 people worldwide.

Subsidiaries Owned by Halliburton

Halliburton presently has no subsidiaries across any sectors.

Halliburton’s LinkedIn Followers

Halliburton’s official LinkedIn profile has approximately 2,732,816 followers.

NAICS Classification of Halliburton

Halliburton is classified under the NAICS code 211, which corresponds to Oil and Gas Extraction.

Halliburton’s Presence on Crunchbase

No, Halliburton does not have a profile on Crunchbase.

Halliburton’s Presence on LinkedIn

Yes, Halliburton maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/halliburton.

Cybersecurity Incidents Involving Halliburton

As of December 11, 2025, Rankiteo reports that Halliburton has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Halliburton has an estimated 10,530 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Halliburton ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

How does Halliburton detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with isolation of affected systems, and recovery measures with restoration of systems with cybersecurity experts, and communication strategy with sec 8-k filing..

Incident Details

Can you provide details on each incident ?

Incident : Cyber Attack

Title: Halliburton Cyberattack (August 2024)

Description: The Halliburton cyberattack, disclosed in an SEC 8-K filing, disrupted operations following an unauthorized system breach on August 21, 2024. The company isolated affected systems, launched an internal and external investigation, and notified law enforcement. While the attack's specifics and extent remain unclear, Halliburton is working with cybersecurity experts to restore systems and ensure safety. This incident highlights the growing cyber threat to critical infrastructure and the energy sector’s need for robust defenses.

Date Detected: 2024-08-21

Type: Cyber Attack

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Cyber Attack HAL650092125

Downtime: True

Which entities were affected by each incident ?

Incident : Cyber Attack HAL650092125

Entity Name: Halliburton

Entity Type: Corporation

Industry: Energy / Oilfield Services

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Cyber Attack HAL650092125

Incident Response Plan Activated: True

Containment Measures: Isolation of affected systems

Recovery Measures: Restoration of systems with cybersecurity experts

Communication Strategy: SEC 8-K filing

Data Breach Information

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by isolation of affected systems and .

Ransomware Information

How does the company recover data encrypted by ransomware ?

Data Recovery from Ransomware: The company recovers data encrypted by ransomware through Restoration of systems with cybersecurity experts, .

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Cyber Attack HAL650092125

Regulatory Notifications: SEC 8-K filing

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Cyber Attack HAL650092125

Lessons Learned: The incident highlights the growing cyber threat to critical infrastructure and the energy sector’s need for robust defenses.

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are The incident highlights the growing cyber threat to critical infrastructure and the energy sector’s need for robust defenses.

References

Where can I find more information about each incident ?

Incident : Cyber Attack HAL650092125

Source: Halliburton SEC 8-K Filing

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Halliburton SEC 8-K Filing.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Cyber Attack HAL650092125

Investigation Status: Ongoing (internal and external investigation launched)

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Sec 8-K Filing.

Post-Incident Analysis

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2024-08-21.

Response to the Incidents

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Isolation of affected systems.

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was The incident highlights the growing cyber threat to critical infrastructure and the energy sector’s need for robust defenses.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Halliburton SEC 8-K Filing.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (internal and external investigation launched).

cve

Latest Global CVEs (Not Company-Specific)

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.

Risk Information
cvss3
Base: 8.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Risk Information
cvss3
Base: 5.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=halliburton' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge