Quick Answer — In early April 2023, Western Digital disclosed a network intrusion that took My Cloud consumer cloud services partially offline — and then came the twist: an attacker claiming responsibility, asserting exfiltration of customer data, staged an extortion with published samples. What WD confirmed: unauthorized access to systems, service disruption, and investigation into scope. The lesson that stood: cloud-tethered storage concentrates risk — your NAS vendor’s incident becomes your availability and confidentiality event.
What happened
- The disclosure (Apr 3): WD reported investigating a “network security incident”; My Cloud, cloud-access, and related services went down or degraded for days — an outage customers experienced as ransomware-like loss of access to their own files.
- The extortion claim: An actor claiming the intrusion posted samples and demanded roughly eight figures, later reportedly negotiating over data deletion — unresolvable publicly (per the actor’s claims to media).
- The recovery arc: Services were restored piecemeal through April; WD’s statements stayed conservative — “working to understand the scope” — while customers waited.
- Historical footnote: Two years prior, the My Book Live wipe attacks (June 2021) had already shown remote-destruct risk on WD’s consumer lines — making 2023’s cloud outage feel like a franchise rerun.
Why cloud-tethered storage concentrates risk
| Property | Consequence |
|---|---|
| Local files gated by vendor cloud | Vendor incident = customer’s LAN storage unavailable |
| Single account plane | Auth compromise reaches every device tied to the account |
| Consumer OTA trust | Firmware update channel = remote code authority over disks |
| Support-old-devices economics | Legacy gear (My Book Live) runs unpatched for years after EOL |
| Mixed brand promises | “Your data stays local” marketing vs cloud-mediated access reality |
Timeline
| Date | Event |
|---|---|
| 2023-03-26 (approx) | Intrusion window begins per later WD statements (hedge: per reporting) |
| 2023-04-03 | WD discloses incident; My Cloud services degraded/offline |
| 2023-04-05 → 17 | Extortion claims reported; partial restorations roll out |
| 2023-04-11 (our peg) | Mid-incident reality: consumer NAS users locked out mid-outage; lessons coalesce |
| 2023-05 → 06 | Services largely restored; data-breach notifications follow where warranted |
| 2021-06 (context) | My Book Live mass-wipe attacks — the earlier chapter of the same trust problem |
Defensive lessons
- Treat cloud-tethered as cloud-dependent. If a vendor outage blocks your LAN files, your availability architecture has a single point far outside your walls — mirror critical data to plain local or independent targets.
- SSH/admin interfaces off by default, always. The 2021 My Book Live wipe chained an unpatched auth bug on an admin port customers forgot existed; 2023’s lesson is the same discipline: interfaces you don’t use, close.
- Buyer-side SLA check for consumer infra. Businesses running on consumer NAS is common and rational until it isn’t; define the RTO you can tolerate, then buy the tier that meets it.
- Extortion ≠ confirmation of scope. Actor claims of “10TB of data” outlived every fact-check; base response on forensics, not press releases from criminals.
- Segment IoT-adjacent storage. NAS devices straddle home-lab and production; keep them on VLANs where a compromise can’t pivot to the flat network.
The two-week status-page era
For customers, the most memorable part of the incident wasn’t any single disclosure — it was the duration: roughly two weeks where the official answer was a service-status page and the unofficial answer was an attacker’s media interviews. That asymmetry defined the trust cost: the attacker communicated more, and faster, than the vendor. Response teams internalized the lesson — incident comms cadence is part of incident response, and silence reads as absence of control even when forensics legitimately demands it. The orgs that later faced their own extortion events borrowed WD’s counter-example: publish early with honest unknowns, update on a fixed rhythm, and never let the criminal own the narrative clock.
Why it still matters in 2026
The WD saga — 2021’s remote wipes plus 2023’s cloud-tethering outage — is the consumer-grade anchor for a lesson enterprises keep relearning at bigger scales: any mediation layer between you and your bytes is a dependency and an attack surface. In 2026, with SaaS outages regularly stranding whole product lines and ransomware crews still pairing encryption with cloud-control-plane abuse, the takeaway scales cleanly: architect so that vendor incidents degrade you gracefully instead of locking you out. The households and small businesses that kept plain local copies in 2023 barely noticed the incident. Everyone else refreshed a status page for two weeks.
Was customer data actually stolen?
Per the actor’s claims, yes — including names and internal material; per WD’s confirmations, the scope stayed under investigation with notifications issued where required. The public record supports “some customer data claim, unverified breadth.” Operational takeaway: treat vendor incidents as data-confidentiality events by default and rotate any credentials stored in or authorized through the affected platform.
Why did services go down during a breach?
Because containment and forensics demand it: credentials revoked, systems isolated, rebuilds staged. A vendor taking its cloud offline mid-incident is doing the correct, painful thing — the design failure was the dependency structure that made containment read as data loss to customers. The outage wasn’t the attack; the outage was the treatment.
How does this connect to the 2021 My Book Live incident?
Same product family, different failure: 2021 was remote destructive exploitation of EOL firmware (devices wiped via exposed admin interfaces); 2023 was vendor-side intrusion with cloud-service fallout. Together they bracket the two risks of tethered storage — the device can be the target, or the vendor can be. A defense plan covering only one is half a plan.
Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.
