hellcat
INACTIVERansomware-as-a-Serviceransomware group
🇯🇴JordanHellCat is a ransomware-as-a-service operation that emerged in late 2024, with KELA researchers identifying core operators including "Rey" (linked to Amman, Jordan) and "Pryx" (an Arabic-speaking operator previously responsible for solo attacks on UAE and Saudi government systems). The group is notable for creative psychological manipulation tactics — including "baguette-themed" ransom demands — and high-profile attacks on Schneider Electric, Orange Group, Telefonica, and Atout France. HellCat shares underlying payload code with the Morpheus ransomware operation, suggesting a common builder or developer, and also has suspected connections to the Scattered Spider ecosystem.
Group Activity
Last 12 monthsVictims (19)
Potomac Financial Services
We have breached a U.S.-based financial services firm. 381GB of sensitive data has been secured. The name will be made public in a few hours. This is a warning.
CVTE
We have breached the internal systems of Guangzhou Shiyuan Electronic Technology, securing sensitive files that, if exposed, would cause serious disruption acro...
HighWire Press
Jiraware <<3 !! We hold sensitive data from HighWire Press, a leading platform serving scholarly publishers. The data includes internal documents, communication...
Racami
Jiraware <<3 !! We have breached Racami’s internal systems. The data in our possession poses a serious threat to their business continuity, reputation, and clie...
Asseco
Jiraware <<3 !! We have breached Asseco’s internal systems, stealing sensitive files, communications, financial records, and source material
LeoVegas AB
We have compromised the internal systems of LeoVegas AB. The data in our possession threatens their operations, regulatory compliance, and customer trust.
Transsion Holdings
We hold almost 70GB of sensitive data from Transsion, a leading mobile device provider with $8.6B in revenue. This includes emails, internal communications, sou...
Grupo Santillana
We hold sensitive files from Santillana, the largest business unit of Spain’s publicly traded Prisa media group. The company must act quickly to prevent the exp...
Omnitracs
We hold sensitive files from Omnitracs, a leading provider of fleet management and logistics solutions. The company must act swiftly to prevent the exposure of...
Electronics For Imaging
We hold 19GB of sensitive files from Electronics For Imaging, Inc., including critical corporate data that could jeopardize the company's operations, client rel...
Ascom Holding AG
44GB of sensitive data including internal reports, sales documents, confidential contracts, development tools, and source code stolen from Ascom.
OneDealer
We have obtained over 330,000 records from OneDealer partners, including sales reports, leads, customer data, and vehicle details with VINs and license plates. ...
Car Care Plan - Turkey
We have successfully stolen over50 GBof data from Car Care Plan, including financial records with sensitive information, legal documents and statements, custome...
Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD)
We have successfully stolen82 GBof data, including backups, from the e-Finance system of Blora Regency, known as theSistem Informasi Pengelolaan Keuangan Daerah...
Pinger - USA
We have successfully breached Pinger, obtaining 111 GB of sensitive data. This includes over 9 million user records, private messages, voice messages, internal ...
College of Business - Tanzania
We have released over 500,000 records from Tanzania’s College of Business Education, containing student names, phone numbers, emails, and additional data, inclu...
Ministry of Education - Jordan
We have successfully accessed and compromised a range of sensitive documents from Jordan's Ministry of Education. This includes images of identification cards, ...
Schneider Electric - France
[IA generated] Schneider Electric, based in France, is a global leader in energy management and automation. The company focuses on digital transformation by int...
The Knesset - Israel
We have successfully compromised the Knesset's secure networks and extracted 64GB of sensitive data. This includes internal communications and confidential docu...
Infrastructure
No sites tracked