Orange România
Incident posture
Linked entities
- Victim
- Orange România
- Threat actors
- 2 actors
- Sources
- 1 source
Timeline
Summary
Orange România was targeted by a hacker known as Rey, who claimed association with the HellCat ransomware group and said he maintained access to the telecom operator’s systems for over a month before extracting data during a three‑hour window without detection. The attacker stated that an extortion
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A hacker using the alias Rey, who is associated with the HellCat ransomware group, claimed responsibility for infiltrating the systems of the French telecommunications company Orange. According to Rey, he maintained access to Orange's networks for more than one month before exfiltrating data during a three‑hour window that went undetected. He stated that the intrusion was achieved through a combination of compromised credentials and a vulnerability in the company's Jira issue‑tracking platform. Rey also noted that internal portals were targeted as part of the same operation.
The data taken primarily concerns Orange Romania and includes approximately 380,000 unique email addresses, internal company documents, and information about customers. Samples of the leaked material show email addresses belonging to current and former employees, partners, and contractors, as well as source code, invoices, contracts, and partial payment‑card details linked to Romanian clients. Some of the email addresses correspond to individuals who have not been Orange Romania customers for over five years, and many of the exposed card details had already expired. In addition, the breach encompassed customer data from Yoxo, Orange's no‑contract subscription service.
Rey asserted that he attempted to extort Orange France but received no response, after which the stolen data were published on a hacker forum. He also said that a ransom note was left on the compromised system, although Orange did not initiate any negotiation regarding the demand. Rey emphasized that the incident was not carried out as part of a HellCat ransomware operation, despite his affiliation with the group.
Sources
Sources available to members: 1 source.