Technical Note

Halliburton Access Remote: The Night a Screen Went Dark and Everything Changed

1785901585
Drilling insight article visual

I've coordinated emergency response in oil and gas for seven years. I've handled rush jobs, last-minute equipment swaps, and more fire drills than I can count. But the night that changed my thinking about remote access wasn't a fire drill. It was a black screen.

At 11:47 PM on a Wednesday in August 2023, our frac engineer in Houston lost the data feed from a wellsite in West Texas. We used a secure portal that we call Halliburton Access Remote—it was the bridge between the field crew and the engineers who could see real-time pressure, rate, and slurry data. When it died, the bridge didn't just wobble. It collapsed.

If you've ever watched a monitoring screen go dark while a job is on the clock, you know the feeling. Your brain starts running through possibilities. Cable. Server. Network. All normal. None right.

People keep asking me, "When did Halliburton get hurt?" The public answer is August 2023, when the company confirmed it was responding to a cyber incident. But the operational answer is darker: the damage started earlier, when we realized our emergency plan had no section for losing remote access.

When Did Halliburton Get Hurt?

Let me back it up.

We were one stage away from finishing a hydraulic fracturing operation. The client needed the final stages done before a weather window closed. The team had already been working long hours. Everyone was tired. Tension was high.

The first sign was the data feed. It just stopped updating. Then the camera went black. Then the portal showed "session disconnected." We did what everyone does: checked the office internet, restarted the viewer, called IT. No luck.

I assumed the problem was a bad cable at the remote site. The classic mistake. Didn't verify. Turned out the issue wasn't physical at all. A third-party vendor's account had been compromised. Someone clicked a link they shouldn't have, and the attacker used that access to disrupt our remote session. Security researchers later linked a similar campaign to a group called Luna Moth. I can't confirm if that's exactly who was behind this one. But the pattern felt familiar.

At that point, Halliburton access remote wasn't just a convenience. It was the entire control loop. Without it, our engineers were blind. The frac crew had local gauges, but they were running a complex pressure-dependent process by feel. That's not a plan. That's a gamble.

The Second Congress That Changed the Decision

We held two emergency meetings that week. The first one was chaos. The client was on one line. The cyber team was on another. The operations manager wanted a timeline. Nobody had one.

The second congress was different. It wasn't a formal Congress, of course—it was our incident review, but calling it a "congress" makes it sound more dignified than it was. The room was quiet, the slides were short, and the options were simple.

Option 1: wait for the investigation to clear the remote access system, then resume operations from Houston. Estimated delay: 4 to 6 days.

Option 2: move two engineers to the wellsite, set up a local command point, and run the next stages manually. Cost: about $38,000 in rush travel, overtime, and satellite internet rentals. Time to re-start: 36 hours.

On paper, option 1 looked cheaper. The list price was lower. No travel, no overtime, no rental fees. But the real cost included the frac crew sitting idle, the drilling schedule slipping, and the weather window closing. If we waited, the client might not have a well to frac at all.

I remember saying to the group: "The cheapest option is not always the least expensive." That line got some eye rolls. But it was true.

We went with option 2. It was the right call.

Luna Moth and the Lessons Nobody Wants to Learn

I'm not a cyber expert. I can't explain the malware, the encryption, or the entry vector. What I can tell you is that every part of the system can fail, and the parts you pay the least attention to fail first.

We spent a lot of money protecting the data centers, the command centers, and the proprietary algorithms. But the attacker didn't need any of that. They needed one vendor with a VPN account and a habit of clicking "renew your password" links. That's not a rare failure. It's the industry's quiet weak spot.

If you want to know how to get eyebrows raised in a boardroom, say: "Our remote monitoring system can be shut down by one phishing email." Watch the silence. Then watch someone mention two-factor authentication. And then you explain that the vendor had it too.

That conversation is more common than most executives want to admit. Looking back, we didn't need a new framework. The NIST Cybersecurity Framework already told us what to do: identify, protect, detect, respond, recover. We were comfortable with the first three. We ignored respond and recover.

After the incident, we changed our emergency response playbook. The biggest change was adding a separate section for loss of remote access. It includes:

  • a list of local personnel who can operate manually at each wellsite
  • pre-approved funding for rush mobilization
  • satellite communication providers to call before the network is down
  • a decision owner who can approve the extra cost without a committee meeting

We also stopped treating Halliburton access remote as an invisible utility. It's not. It's a critical piece of infrastructure. It needs a backup, an owner, and a monthly test.

What I'd Tell Anyone Facing the Same Problem

If you're reading this because you're in the middle of an emergency, here's the practical part.

First, decide how much time you actually have. Not "as soon as possible"—specific hours. In our case, we had 36 hours before the weather window was gone.

Second, ask what the worst case is. Not the best case, not the most likely case. The worst case. Our worst case was the client abandoning the well location. That made the $38,000 decision easy.

Third, don't trust a plan that starts with "probably." "Probably we'll be back online by tomorrow" is not a plan. It's hope. Hope doesn't hold up under pressure.

"In an emergency, certainty is not a premium feature. It's the whole product."

I still remember the moment the manual team radioed in and said the final stage was pumping. The results weren't as smooth as they would have been with real-time optimization from Houston. But they were solid. We made the deadline. We lost margin on that job, and we kept a client.

So when did Halliburton get hurt? It wasn't when the news went out. It wasn't when the investigation started. It was the moment we discovered that the thing we trusted most could disappear without warning.

Halliburton access remote works best when you trust it. But trust is not a control. Verify your access, plan for the black screen, and keep your emergency playbook close.

Because the screen can go dark at 11:47 PM. I've seen it.

Halliburton Engineering Editorial Team

Our technical articles are developed to help project teams connect equipment selection, service planning, and operational learning in one readable format.