Schneider Electric investigated Hellcat theft of 40GB from its Jira server

Organization
Schneider Electric
Exploit
Ransomware
Industry
Energy

Schneider Electric confirmed in early November 2024 that it was investigating unauthorized access to one of its internal project execution tracking platforms, which the French energy management company said was hosted in an isolated environment. It said its products and services were unaffected and that its global incident response team had been mobilized.

The claim came from Hellcat, a then newly formed extortion group, through a member using the handle Grep. Hellcat said it had reached Schneider Electric's Jira instance and taken more than 40GB of compressed data covering projects, issues, plugins and over 400,000 rows of user data. The group posted screenshots on X that it said demonstrated its access.

The demand was unusual. Hellcat asked for $125,000 and said on its leak site that it would take payment in French bread, a jab at the company's headquarters, while in practice wanting Monero. According to SecurityWeek, the group also offered to halve the figure if Schneider Electric publicly acknowledged the breach. Researchers read the stunt as an attempt by a new crew to build credibility ahead of a ransomware-as-a-service operation.

Schneider Electric did not confirm the volume of data taken and did not say whether it would pay. The incident followed a January 2024 attack on the company's Sustainability Business division by the Cactus ransomware group, making it at least the second publicly reported intrusion at the company that year.

Sources