logo

Baguette bandits strike again with ransomware and a side of mockery

ID: d263c4c3-65de-5727-9231-4d24e8de5745

STIX ID: report--d263c4c3-65de-5727-9231-4d24e8de5745

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-01-28

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Hellcat is an emerging ransomware-as-a-service group active since mid-2024 that has targeted government, education, energy, and telecom organizations using double-extortion tactics and publicly humiliating victims. Notable activity includes a claimed Schneider Electric breach (40GB stolen and subsequent leak of 75,000 email addresses), large-scale data leaks and sales (including claims affecting Tanzania and Jordan), and exploitation of a previously unknown Atlassian Jira vulnerability to gain access; the group also advertises root access and stolen datasets for sale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.