Data leak

Orange Romania HellCat/Rey Data Breach - 600K Records

πŸ“… 2024-12-01 🏒 Atlassian Jira (project management platform)
Primary Source β†—

Incident Details

In early 2025, the HellCat-affiliated threat actor ‘Rey’ exfiltrated 6.5 GB of data (12,000 files) from Orange Romania’s back-office systems, resulting in exposure of over 600,000 records including approximately 380,000 unique email addresses, source code, invoices, contracts, customer data, and partial payment card details. Rey claimed the breach stemmed from compromised credentials and Jira vulnerabilities and maintained access for over a month. After Orange declined ransom negotiations, Rey leaked the data on BreachForums. Orange characterized the breach as affecting a non-critical system with no impact on customer operations. Have I Been Pwned indexed the breach.

Technical Details

Initial Attack Vector
Compromised credentials and vulnerabilities in Orange Romania's Jira software and internal portals; attacker had access for over one month
Vendor / Product
Atlassian Jira (project management platform)

Timeline

  1. 2024-12-01 Breach occurred
  2. 2025-02-01 Publicly disclosed
  3. 2025-02-01 Customers notified