Back to Threat Groups

hellcat

INACTIVERansomware-as-a-Service

ransomware group

🇯🇴Jordan

HellCat is a ransomware-as-a-service operation that emerged in late 2024, with KELA researchers identifying core operators including "Rey" (linked to Amman, Jordan) and "Pryx" (an Arabic-speaking operator previously responsible for solo attacks on UAE and Saudi government systems). The group is notable for creative psychological manipulation tactics — including "baguette-themed" ransom demands — and high-profile attacks on Schneider Electric, Orange Group, Telefonica, and Atout France. HellCat shares underlying payload code with the Morpheus ransomware operation, suggesting a common builder or developer, and also has suspected connections to the Scattered Spider ecosystem.

Victims
19
records
First Discovered
Oct 25, 2024
victim
Last Discovered
Apr 10, 2025
victim
Inactive Since
442
days
Countries
13
hit
Avg Discount
no settlements

Group Activity

Last 12 months
Jul
2025
Aug
2025
Sep
2025
Oct
2025
Nov
2025
Dec
2025
Jan
2026
Feb
2026
Mar
2026
Apr
2026
May
2026
Jun
2026

Victims (19)

Potomac Financial Services

hellcat🇺🇸 US
Apr 10, 2025

We have breached a U.S.-based financial services firm. 381GB of sensitive data has been secured. The name will be made public in a few hours. This is a warning.

Financial Services5.0Published
potomacfinancialadvisors.com

CVTE

hellcat🇨🇳 CN
Apr 7, 2025

We have breached the internal systems of Guangzhou Shiyuan Electronic Technology, securing sensitive files that, if exposed, would cause serious disruption acro...

Technology5.0Published
cvte.com

HighWire Press

hellcat🇺🇸 US
Apr 5, 2025

Jiraware <<3 !! We hold sensitive data from HighWire Press, a leading platform serving scholarly publishers. The data includes internal documents, communication...

Technology5.0Published
highwirepress.com

Racami

hellcat🇺🇸 US
Apr 5, 2025

Jiraware <<3 !! We have breached Racami’s internal systems. The data in our possession poses a serious threat to their business continuity, reputation, and clie...

Technology1.0Published
racami.com

Asseco

hellcat🇵🇱 PL
Apr 5, 2025

Jiraware <<3 !! We have breached Asseco’s internal systems, stealing sensitive files, communications, financial records, and source material

Technology7.0Published
asseco.com

LeoVegas AB

hellcat🇸🇪 SE
Apr 5, 2025

We have compromised the internal systems of LeoVegas AB. The data in our possession threatens their operations, regulatory compliance, and customer trust.

Telecommunication3.0Published
leovegasgroup.com

Transsion Holdings

hellcat🇨🇳 CN2 groups: quantum
Mar 29, 2025

We hold almost 70GB of sensitive data from Transsion, a leading mobile device provider with $8.6B in revenue. This includes emails, internal communications, sou...

Technology6.0Published
transsion.com

Grupo Santillana

hellcat🇪🇸 ES
Mar 25, 2025

We hold sensitive files from Santillana, the largest business unit of Spain’s publicly traded Prisa media group. The company must act quickly to prevent the exp...

Education5.0Published
santillana.com

Omnitracs

hellcat🇺🇸 US
Mar 25, 2025

We hold sensitive files from Omnitracs, a leading provider of fleet management and logistics solutions. The company must act swiftly to prevent the exposure of...

Technology5.0Published
omnitracs.com

Electronics For Imaging

hellcat🇺🇸 US
Mar 17, 2025

We hold 19GB of sensitive files from Electronics For Imaging, Inc., including critical corporate data that could jeopardize the company's operations, client rel...

Technology7.0Published
efi.com

Ascom Holding AG

hellcat🇨🇭 CH
Mar 16, 2025

44GB of sensitive data including internal reports, sales documents, confidential contracts, development tools, and source code stolen from Ascom.

Technology7.0Published
ascom.com

OneDealer

hellcat🇩🇪 DE
Feb 28, 2025

We have obtained over 330,000 records from OneDealer partners, including sales reports, leads, customer data, and vehicle details with VINs and license plates. ...

Consumer Services6.0Published
onedealer.com

Car Care Plan - Turkey

hellcat🇹🇷 TR
Dec 26, 2024

We have successfully stolen over50 GBof data from Car Care Plan, including financial records with sensitive information, legal documents and statements, custome...

Financial7.0Published
carcareplan.com.tr

Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD)

hellcat🇮🇩 ID
Dec 25, 2024

We have successfully stolen82 GBof data, including backups, from the e-Finance system of Blora Regency, known as theSistem Informasi Pengelolaan Keuangan Daerah...

Government7.0Published
kemendagri.go.id

Pinger - USA

hellcat🇺🇸 US
Dec 25, 2024

We have successfully breached Pinger, obtaining 111 GB of sensitive data. This includes over 9 million user records, private messages, voice messages, internal ...

Business Services7.0Published
pinger.com

College of Business - Tanzania

hellcat🇹🇿 TZ
Nov 4, 2024

We have released over 500,000 records from Tanzania’s College of Business Education, containing student names, phone numbers, emails, and additional data, inclu...

Education6.0Published
cbe.ac.tz

Ministry of Education - Jordan

hellcat🇯🇴 JO
Nov 4, 2024

We have successfully accessed and compromised a range of sensitive documents from Jordan's Ministry of Education. This includes images of identification cards, ...

Education7.0Published
moe.gov.jo

Schneider Electric - France

hellcat🇫🇷 FR
Nov 4, 2024

[IA generated] Schneider Electric, based in France, is a global leader in energy management and automation. The company focuses on digital transformation by int...

Energy1.0Published
se.com

The Knesset - Israel

hellcat🇮🇱 IL
Oct 25, 2024

We have successfully compromised the Knesset's secure networks and extracted 64GB of sensitive data. This includes internal communications and confidential docu...

Government5.0Published
knesset.gov.il

Infrastructure

No sites tracked