CSIDB logo
Incident

Orange România

Incident posture

Attack window
Oct 2025
Location
Romania
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 02:04

Linked entities

Victim
Orange România
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Pending

Summary

Orange România was targeted by a hacker known as Rey, who claimed association with the HellCat ransomware group and said he maintained access to the telecom operator’s systems for over a month before extracting data during a three‑hour window without detection. The attacker stated that an extortion

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

A hacker using the alias Rey, who is associated with the HellCat ransomware group, claimed responsibility for infiltrating the systems of the French telecommunications company Orange. According to Rey, he maintained access to Orange's networks for more than one month before exfiltrating data during a three‑hour window that went undetected. He stated that the intrusion was achieved through a combination of compromised credentials and a vulnerability in the company's Jira issue‑tracking platform. Rey also noted that internal portals were targeted as part of the same operation.

The data taken primarily concerns Orange Romania and includes approximately 380,000 unique email addresses, internal company documents, and information about customers. Samples of the leaked material show email addresses belonging to current and former employees, partners, and contractors, as well as source code, invoices, contracts, and partial payment‑card details linked to Romanian clients. Some of the email addresses correspond to individuals who have not been Orange Romania customers for over five years, and many of the exposed card details had already expired. In addition, the breach encompassed customer data from Yoxo, Orange's no‑contract subscription service.

Rey asserted that he attempted to extort Orange France but received no response, after which the stolen data were published on a hacker forum. He also said that a ransom note was left on the compromised system, although Orange did not initiate any negotiation regarding the demand. Rey emphasized that the incident was not carried out as part of a HellCat ransomware operation, despite his affiliation with the group.

Sources

Sources available to members: 1 source.

CSIDB