Orange Group confirms breach of Romanian back office systems
- Organization
- Orange Group
- Exploit
- Hacking
- Industry
- Telecommunications
Orange Group, the French telecommunications operator, confirmed in late February 2025 that an intruder had accessed systems belonging to its Romanian business. The company said the compromise was limited to a non-critical back office application and that there had been no impact on customer operations.
A threat actor using the alias Rey claimed responsibility and published the stolen material after the company did not respond to an extortion attempt. Rey said access had been maintained for more than a month using compromised credentials and weaknesses in Orange's Jira issue tracking software and internal portals, and that the data was pulled out over roughly three hours.
The leaked archive ran to about 6.5GB across roughly 12,000 files. According to BleepingComputer, it contained around 380,000 unique email addresses along with source code, invoices, contracts, employee and contractor records, partial payment card details belonging to Romanian customers, and email addresses and names of subscribers to Orange's Yoxo service. Some records related to people who had worked with the company more than five years earlier.
Rey was associated with the HellCat extortion group but described the Orange intrusion as an independent operation rather than a HellCat ransomware deployment. Orange said it had opened an investigation with its cybersecurity teams, was working to limit the impact, and would meet its obligations to notify authorities and affected individuals.