• News/
  • https://www.theregister.com/2025/01/28/baguettes_bandits_strike_again/

Baguette bandits strike again with ransomware and a side of mockery

The Register
·
Jessica Lyons
·
Published Jan 28, 2025
·
Updated

Hellcat, the ransomware crew that infected Schneider Electric and demanded $125,000 in baguettes, has aggressively targeted government, education, energy, and other critical industries since it emerged around mid-2024. Like many of the emerging cybercrime organizations, Hellcat uses a ransomware-as-a-service business model, offering infrastructure, encryption tools, and other malware to affiliates in exchange for a portion of the profits. Its primary operators seem to be high-ranking BreachForums members [PDF]. Hellcat also uses double-extortion tactics, as do most ransomware gangs these days. First, it breaks into victims' networks and steals their files, then it locks up the data and threatens to leak or sell sensitive information if the organization doesn't pay the extortion demand. But what makes this group especially concerning, according to threat researchers, is its high-profile targets and penchant for humiliating its victims. This was the case with the November Schneider Electric attack, during which the criminals claimed to have stolen 40GB of compressed data. Before leaking 75,000 email addresses and full names of Schneider Electric employees and customers, Hellcat demanded that the French energy management giant pay $125,000 in baguettes. Humiliation is a major psychological tactic leveraged by Hellcat The move was intended "to further mock the company," Cato Networks Chief Security Strategist Etay Maor said in a report published on Tuesday. "Humiliation is a majo...

Read full article

Affected Software

2 affected components
Atlassian Jira
Schneider Electric Electric
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the ransomware group Hellcat, notorious for targeting critical industries and demanding payment in baguettes.

2

What security implications are discussed?

The article highlights the increasing threat posed by ransomware attacks on vital sectors such as government, education, and energy.

3

What products or software are affected by the ransomware attacks?

The article mentions that Atlassian Jira and Schneider Electric's software are among those impacted by the Hellcat ransomware attacks.

4

When did the ransomware group Hellcat first emerge?

Hellcat first emerged around mid-2024 and has since aggressively targeted various industries.

5

What unique demand did Hellcat make in their ransom note?

The ransomware group Hellcat demanded payment specifically in baguettes, adding a layer of mockery to their criminal activities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203