Hewlett Packard Enterprise (HPE) disclosed that attackers exposed a “limited subset” of Aruba Central customer data.

The attackers accessed the Aruba Central cloud environment using an unauthorized access key and exposed two data repositories, according to an HPE security advisory.

One contained network telemetry data for most Aruba Central customers about WiFi client devices connected to customer WiFi networks. This data feeds machine learning algorithms that power the Aruba Central AI Insights feature, which analyzes network behavior and performance and makes predictive recommendations to network administrators.

The second Aruba Central data repository contained location-oriented data about WiFi client devices including which ones were in proximity to other WiFi client devices. This powers Aruba’s Contact Tracing service.

However, the attackers only stole “a very small amount” of customer data, “if any at all,” according to HPE.

“Aruba engineers have analyzed the usage records of the exposed repositories and have correlated those records with known, authorized activity,” the security alert says. “The remaining unexplained activity represents a negligible proportion of all the data stored in the repositories. This lets us state definitively that the unauthorized actor did not view, download, or transfer out of the repositories any significant amount of data.”

Attackers Gained Access on Oct. 9

HPE’s security advisory comes more than a month after the attackers first used the access key on Oct. 9. However, HPE automatically decommissioned and rotated that key on Oct. 27, as part of its regular security protocols, which means the old key has been invalid since then.

Monitoring tools deployed inside the cloud environment alerted the security operations team about the suspicious activity, and on Nov. 2 the Aruba Central team concluded the data repositories had been breached by an unauthorized user.

The security team is working to improve its policies and access-key tools to prevent a future breach, according to HPE. “The Aruba Central team is accelerating an existing project to minimize the use of access keys in favor of identity and access management (IAM) features of the cloud platform,” the security advisory says. “Any keys used outside the environment will be subjected to stricter policies and more in-depth monitoring.”