Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Schneider Electric Jira Breach 2024: How Infostealer Credentials…
Breach analysis Incident: 2 Nov 2024

Schneider Electric Jira Breach 2024: How Infostealer Credentials Led to 40GB of Project Data Being Stolen

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: Human identity
Attack route: Stolen credentials
On this page

In November 2024, Schneider Electric confirmed "unauthorized access to one of our internal project execution tracking platforms," a Jira server hosted in an isolated environment. A hacker known as Grep, part of the newly named Hellcat ransomware group, told BleepingComputer they got in using exposed credentials, then used a MiniOrange REST API to scrape about 400,000 rows of user data, including 75,000 unique email addresses and full names of employees and customers. Hellcat claimed more than 40GB of compressed data, including projects, issues and plugins, and demanded $125,000 "in Baguettes," halved if Schneider Electric publicly confirmed the breach. Infostealer intelligence firm Hudson Rock reported that a Schneider Electric employee's computer had been infected by the Lumma infostealer on 13 October 2024, and that credentials on it directly matched Grep's account of the breach. The same machine also held Jira-related credentials for accounts named "cloud_migration" and "jira_migration." Schneider Electric said its products and services were unaffected.

Key takeaways

  • Schneider Electric confirmed unauthorised access to an internal Jira project tracking platform in November 2024.
  • The attacker said they used exposed credentials, then scraped 400,000 rows of user data through a REST API.
  • Hudson Rock matched the attacker's claims to credentials stolen from an employee's computer by the Lumma infostealer.
  • Hellcat claimed 40GB of data and demanded $125,000, halved if the company confirmed the breach.
  • The identity lesson: infostealers turn a single infected laptop into a set of working logins, including for migration and service accounts stored alongside personal ones.

At a glance

OrganisationSchneider Electric (energy management and automation)
WhenEmployee device infected 13 October 2024; breach claimed 2 November; confirmed 4 November 2024
AttackerHellcat ransomware group; the hacker known as Grep
Entry pointCredentials stolen by the Lumma infostealer from an employee's computer, according to Hudson Rock
Identities abusedJira credentials; the same device also held credentials for "cloud_migration" and "jira_migration" accounts
Impact40GB of Jira data claimed stolen, including 400,000 rows of user data; extortion demand
CategoryHuman identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (infostealer-stolen credentials)

What happened

ITPro reported that the incident "was first brought to light on 2 November when the HellCat ransomware collective posted to their leak site on the dark web claiming to have breached Schneider Electric's infrastructure." The listing said: "This breach has compromised critical data, including projects, issues, and plugins, along with over 400,000 rows of user data, totally more than 40GB Compressed Data." Schneider Electric told BleepingComputer: "Schneider Electric is investigating a cybersecurity incident involving unauthorized access to one of our internal project execution tracking platforms which is hosted within an isolated environment," adding that "Schneider Electric's products and services remain unaffected."

Grep told BleepingComputer they "breached Schneider Electric's Jira server using exposed credentials. Once they gained access, they claimed to use a MiniOrange REST API to scrape 400k rows of user data, which Grep says includes 75,000 unique email addresses and full names for Schneider Electric employees and customers." CyberScoop quoted the ransom note: "To secure the deletion of this data and prevent its public release, we require a payment of $125,000 USD in Baguettes."

Hudson Rock linked the credentials to an infostealer. Its researchers "identified a Schneider Electric employee infected by Lumma Infostealer on October 13, 2024," likely while downloading a cracked copy of Adobe Premiere, and "found a direct match between Grep's assertions and credentials on the compromised computer." It added that the machine "held other sensitive Jira-related credentials belonging to the organization, with usernames like 'cloud_migration' and 'jira_migration'." Hudson Rock did not say which account was used to log in. CyberScoop noted this was the third attack on Schneider Electric in 18 months, after Cactus ransomware in January 2024 and the MOVEit campaign in 2023.

Timeline

DateEvent
13 October 2024An employee's computer is infected by the Lumma infostealer, according to Hudson Rock.
2 November 2024Hellcat claims the breach on its leak site.
4 November 2024Schneider Electric confirms unauthorised access to its Jira platform.
5 November 2024Hudson Rock publishes its infostealer findings; CyberScoop and ITPro report the incident.

How it happened: the identity attack path

  1. Infostealer infection. An employee's computer was infected by Lumma, which harvested stored credentials.
  2. Credentials obtained. Credentials matching the attacker's account of the breach were on that machine.
  3. Jira access. The attacker logged into Schneider Electric's Jira server.
  4. Data scraped. A REST API was used to pull 400,000 rows of user data and project content.
  5. Extortion. Hellcat demanded $125,000 and threatened to publish the data.

Impact

  • Data: 40GB of compressed Jira data claimed, including projects, issues, plugins and 400,000 rows of user data.
  • People: 75,000 unique email addresses and names of employees and customers, according to the attacker.
  • Operations: products and services unaffected, according to Schneider Electric.

What this means for NHI governance

This is a human-identity breach, flagged as such on our breach hub: the sources tie the entry to credentials stolen from an employee's computer. We include it because of what else was on that machine. Credentials for accounts named "cloud_migration" and "jira_migration" look like service or migration accounts, and storing them in a browser on a personal-use laptop puts them one infostealer away from an attacker. Migration accounts are often created for a project, given broad access and never removed.

Keep service and migration credentials in a vault, never in browsers, and decommission them when the work ends. Watch infostealer intelligence for your own domains. See our Service Account Security Guide and Joiner-Mover-Leaver Guide.

Recommendations

  • Require MFA on collaboration tools. Jira and Confluence hold sensitive data and need strong login. See our MFA Guide.
  • Keep service credentials out of browsers. Store migration and service accounts in a vault. See the Service Account Security Guide.
  • Retire project accounts. Remove migration accounts when the migration ends. See the NHI Ownership Guide.
  • Monitor infostealer exposure. Reset credentials found in infostealer logs. See the Leaked Credential Response Playbook.
  • Limit bulk API reads. Alert on scraping of user directories through plugin APIs. See the ITDR Guide.

Frequently asked questions

How was Schneider Electric breached in 2024?

The attacker said they used exposed credentials to log into a Jira server. Hudson Rock linked those credentials to an employee's computer infected by the Lumma infostealer.

What data was stolen from Schneider Electric?

Hellcat claimed 40GB of compressed Jira data, including projects, issues, plugins and 400,000 rows of user data with 75,000 unique email addresses.

Who was behind the Schneider Electric attack?

The Hellcat ransomware group, including a hacker known as Grep.

Snowflake Breach 2024 · Cisco DevHub Breach 2024 · Service Account Security Guide · MFA Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Infostealers harvest every credential on a device, human or not. We help teams keep service accounts off endpoints, retire old ones and respond fast to stolen logins. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org