Ransomware

Schneider Electric Hellcat Ransomware Attack

πŸ“… 2024-11-01 🏒 Atlassian Jira 🦠 Hellcat
Primary Source β†—

Incident Details

Hellcat ransomware group breached Schneider Electric’s internal Atlassian Jira project tracking platform in November 2024, stealing over 40 GB of compressed data including 75,000 unique email addresses and 400,000+ rows of user/project data. Attackers demanded $125,000 paid in Monero (mockingly framed as ‘baguettes’). After Schneider declined, Hellcat published the 40 GB dataset on 31 December 2024. This was Schneider Electric’s third cybersecurity incident in 18 months.

Technical Details

Initial Attack Vector
Hellcat ransomware group accessed Schneider Electric's Atlassian Jira instance using the MiniOrange REST API to extract data
Vendor / Product
Atlassian Jira
Malware Family
Hellcat

Timeline

  1. 2024-11-01 Breach occurred
  2. 2024-11-04 Publicly disclosed