Ransomware
Schneider Electric Hellcat Ransomware Attack
Primary Source βIncident Details
Hellcat ransomware group breached Schneider Electric’s internal Atlassian Jira project tracking platform in November 2024, stealing over 40 GB of compressed data including 75,000 unique email addresses and 400,000+ rows of user/project data. Attackers demanded $125,000 paid in Monero (mockingly framed as ‘baguettes’). After Schneider declined, Hellcat published the 40 GB dataset on 31 December 2024. This was Schneider Electric’s third cybersecurity incident in 18 months.
Technical Details
- Initial Attack Vector
- Hellcat ransomware group accessed Schneider Electric's Atlassian Jira instance using the MiniOrange REST API to extract data
- Vendor / Product
- Atlassian Jira
- Malware Family
- Hellcat
Timeline
- 2024-11-01 Breach occurred
- 2024-11-04 Publicly disclosed