BreachCensus

hellcat

First seen October 25, 2024Active20 claimed victims

The claims below are reproduced as posted by hellcat on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
CVTEApril 7, 2025ransomware_live
P**o***April 7, 2025ransomware_live
Potomac Financial ServicesApril 7, 2025ransomware_live
LeoVegas ABApril 5, 2025ransomware_live
AssecoApril 5, 2025ransomware_live
RacamiApril 5, 2025ransomware_live
Transsion HoldingsMarch 29, 2025ransomware_live
OmnitracsMarch 24, 2025ransomware_live
Grupo SantillanaMarch 24, 2025ransomware_live
HighWire PressMarch 18, 2025ransomware_live
Electronics For ImagingMarch 17, 2025ransomware_live
Ascom Holding AGMarch 15, 2025ransomware_live
OneDealerFebruary 25, 2025ransomware_live
Car Care Plan - TurkeyDecember 26, 2024ransomware_live
Pinger - USADecember 25, 2024ransomware_live
Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD)December 25, 2024ransomware_live
Schneider Electric - FranceNovember 4, 2024ransomware_live
Ministry of Education - JordanNovember 4, 2024ransomware_live
College of Business - TanzaniaNovember 4, 2024ransomware_live
The Knesset - IsraelOctober 25, 2024ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).