In November 2024, Schneider Electric confirmed "unauthorized access to one of our internal project execution tracking platforms," a Jira server hosted in an isolated environment. A hacker known as Grep, part of the newly named Hellcat ransomware group, told BleepingComputer they got in using exposed credentials, then used a MiniOrange REST API to scrape about 400,000 rows of user data, including 75,000 unique email addresses and full names of employees and customers. Hellcat claimed more than 40GB of compressed data, including projects, issues and plugins, and demanded $125,000 "in Baguettes," halved if Schneider Electric publicly confirmed the breach. Infostealer intelligence firm Hudson Rock reported that a Schneider Electric employee's computer had been infected by the Lumma infostealer on 13 October 2024, and that credentials on it directly matched Grep's account of the breach. The same machine also held Jira-related credentials for accounts named "cloud_migration" and "jira_migration." Schneider Electric said its products and services were unaffected.
Key takeaways
- Schneider Electric confirmed unauthorised access to an internal Jira project tracking platform in November 2024.
- The attacker said they used exposed credentials, then scraped 400,000 rows of user data through a REST API.
- Hudson Rock matched the attacker's claims to credentials stolen from an employee's computer by the Lumma infostealer.
- Hellcat claimed 40GB of data and demanded $125,000, halved if the company confirmed the breach.
- The identity lesson: infostealers turn a single infected laptop into a set of working logins, including for migration and service accounts stored alongside personal ones.
At a glance
| Organisation | Schneider Electric (energy management and automation) |
|---|---|
| When | Employee device infected 13 October 2024; breach claimed 2 November; confirmed 4 November 2024 |
| Attacker | Hellcat ransomware group; the hacker known as Grep |
| Entry point | Credentials stolen by the Lumma infostealer from an employee's computer, according to Hudson Rock |
| Identities abused | Jira credentials; the same device also held credentials for "cloud_migration" and "jira_migration" accounts |
| Impact | 40GB of Jira data claimed stolen, including 400,000 rows of user data; extortion demand |
| Category | Human identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (infostealer-stolen credentials) |
What happened
ITPro reported that the incident "was first brought to light on 2 November when the HellCat ransomware collective posted to their leak site on the dark web claiming to have breached Schneider Electric's infrastructure." The listing said: "This breach has compromised critical data, including projects, issues, and plugins, along with over 400,000 rows of user data, totally more than 40GB Compressed Data." Schneider Electric told BleepingComputer: "Schneider Electric is investigating a cybersecurity incident involving unauthorized access to one of our internal project execution tracking platforms which is hosted within an isolated environment," adding that "Schneider Electric's products and services remain unaffected."
Grep told BleepingComputer they "breached Schneider Electric's Jira server using exposed credentials. Once they gained access, they claimed to use a MiniOrange REST API to scrape 400k rows of user data, which Grep says includes 75,000 unique email addresses and full names for Schneider Electric employees and customers." CyberScoop quoted the ransom note: "To secure the deletion of this data and prevent its public release, we require a payment of $125,000 USD in Baguettes."
Hudson Rock linked the credentials to an infostealer. Its researchers "identified a Schneider Electric employee infected by Lumma Infostealer on October 13, 2024," likely while downloading a cracked copy of Adobe Premiere, and "found a direct match between Grep's assertions and credentials on the compromised computer." It added that the machine "held other sensitive Jira-related credentials belonging to the organization, with usernames like 'cloud_migration' and 'jira_migration'." Hudson Rock did not say which account was used to log in. CyberScoop noted this was the third attack on Schneider Electric in 18 months, after Cactus ransomware in January 2024 and the MOVEit campaign in 2023.
Timeline
| Date | Event |
|---|---|
| 13 October 2024 | An employee's computer is infected by the Lumma infostealer, according to Hudson Rock. |
| 2 November 2024 | Hellcat claims the breach on its leak site. |
| 4 November 2024 | Schneider Electric confirms unauthorised access to its Jira platform. |
| 5 November 2024 | Hudson Rock publishes its infostealer findings; CyberScoop and ITPro report the incident. |
How it happened: the identity attack path
- Infostealer infection. An employee's computer was infected by Lumma, which harvested stored credentials.
- Credentials obtained. Credentials matching the attacker's account of the breach were on that machine.
- Jira access. The attacker logged into Schneider Electric's Jira server.
- Data scraped. A REST API was used to pull 400,000 rows of user data and project content.
- Extortion. Hellcat demanded $125,000 and threatened to publish the data.
Impact
- Data: 40GB of compressed Jira data claimed, including projects, issues, plugins and 400,000 rows of user data.
- People: 75,000 unique email addresses and names of employees and customers, according to the attacker.
- Operations: products and services unaffected, according to Schneider Electric.
What this means for NHI governance
This is a human-identity breach, flagged as such on our breach hub: the sources tie the entry to credentials stolen from an employee's computer. We include it because of what else was on that machine. Credentials for accounts named "cloud_migration" and "jira_migration" look like service or migration accounts, and storing them in a browser on a personal-use laptop puts them one infostealer away from an attacker. Migration accounts are often created for a project, given broad access and never removed.
Keep service and migration credentials in a vault, never in browsers, and decommission them when the work ends. Watch infostealer intelligence for your own domains. See our Service Account Security Guide and Joiner-Mover-Leaver Guide.
Recommendations
- Require MFA on collaboration tools. Jira and Confluence hold sensitive data and need strong login. See our MFA Guide.
- Keep service credentials out of browsers. Store migration and service accounts in a vault. See the Service Account Security Guide.
- Retire project accounts. Remove migration accounts when the migration ends. See the NHI Ownership Guide.
- Monitor infostealer exposure. Reset credentials found in infostealer logs. See the Leaked Credential Response Playbook.
- Limit bulk API reads. Alert on scraping of user directories through plugin APIs. See the ITDR Guide.
Frequently asked questions
How was Schneider Electric breached in 2024?
The attacker said they used exposed credentials to log into a Jira server. Hudson Rock linked those credentials to an employee's computer infected by the Lumma infostealer.
What data was stolen from Schneider Electric?
Hellcat claimed 40GB of compressed Jira data, including projects, issues, plugins and 400,000 rows of user data with 75,000 unique email addresses.
Who was behind the Schneider Electric attack?
The Hellcat ransomware group, including a hacker known as Grep.
Related NHI Mgmt Group resources
Snowflake Breach 2024 · Cisco DevHub Breach 2024 · Service Account Security Guide · MFA Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Infostealers harvest every credential on a device, human or not. We help teams keep service accounts off endpoints, retire old ones and respond fast to stolen logins. See our NHI and AI agent security training.
References
- BleepingComputer: Schneider Electric confirms dev platform breach after hacker steals data (4 November 2024)
- Hudson Rock (Infostealers.com): Schneider Electric Hacked and Blackmailed Following Lumma Infostealer Infection (5 November 2024)
- ITPro: Schneider Electric confirms breach after hacker claims to have 40GB of stolen data (5 November 2024)
- CyberScoop: Schneider Electric reports cyberattack, its third incident in 18 months (5 November 2024)