Ransomware group

Hellcat ransomware: victims and leak site activity

The Hellcat ransomware group has listed 20 victims on its leak site since October 2024; its latest post is from 10 April 2025. Most affected countries: United States, China and Switzerland. Most targeted sector: Technology.

Total posts 20
First seen 2024-10-25
Latest post 2025-04-10
Countries hit 13

About Hellcat

HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.

Leak site (Tor)
http://hcatxn4ppkgmakaatrq6bsbhqk5ouhviygyx57gljjt5iseul5nvpayd.onion

Hellcat victims per year

7 2024
13 2025

All 20 victims

Search every post in the full table.
Victim Country Sector Discovered
Potomac Financial Services United States Financial Services
P**o*** Financial Services
CVTE China Technology
HighWire Press United States Technology
Racami United States Technology
Asseco Poland Technology
LeoVegas AB Sweden Technology
Transsion Holdings China Technology
Grupo Santillana Spain Education
Omnitracs United States Technology
Electronics For Imaging United States Technology
Ascom Holding AG Switzerland Technology
OneDealer Germany Retail & E-Commerce
Car Care Plan - Turkey Turkey Retail & E-Commerce
Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD) Indonesia Government & Defense
Pinger - USA United States Professional Services
College of Business - Tanzania Tanzania Education
Ministry of Education - Jordan Jordan Education
Schneider Electric - France France Energy & Utilities
The Knesset - Israel Israel Government & Defense