Lessons from Hellcat’s Jira breaches
Identity-based attacks on the rise in 2025: no zero-days, no novel malware, just stolen logins.
In early 2025, a hacking crew known as Hellcat stormed through a string of high-profile companies. Not with novel malware or zero-day exploits, but with something far more mundane: stolen login credentials. By simply logging in to enterprise Jira systems with usernames and passwords obtained on the dark web, Hellcat breached multiple organisations and demanded ransoms. In March alone, the group hit at least three major enterprises through their Jira environments.
These incidents underscore a crucial shift in the threat landscape: when it comes to breaches, identity is now often the weakest link. This article looks at Hellcat’s tactics and the broader trend of identity-based attacks, with lessons for security leaders.
Hellcat’s credential-fuelled crime spree
Hellcat burst onto the scene in late 2024 and quickly gained notoriety for targeting companies through their Atlassian Jira platforms. The method is alarmingly straightforward: find or buy valid user credentials, log in to a company’s Jira or related cloud service, and help yourself to sensitive data. One report counted six breaches in five months using stolen logins.
Once inside, the group explored project tickets, attachments, wikis and integrated apps for valuable information. In the breach of Swiss telecom Ascom on 16 March, Hellcat stole around 44 GB of data including source code, project plans, invoices and support tickets. Around the same time they raided the Jira workspace of Affinitiv, a US marketing analytics company, taking databases holding about 470,000 customer emails and marketing records.
An infostealer that hit a partner company years earlier ultimately led to the breach.
The most publicised case was Jaguar Land Rover. Hellcat obtained internal documents, source code and employee data from the carmaker’s Jira system and leaked around 700 files. When JLR didn’t meet their demands, the group tried to sell 350 GB of stolen data on hacker forums, pointing to a second, deeper round of compromise using the same credentials.
Why were these targets so easy to breach? In each case initial access needed nothing more than a valid username and password. Hellcat operatives scoured illicit marketplaces for credentials, using info-stealer logs and old database leaks. Hudson Rock research showed that JLR’s Jira credentials had been stolen from an employee at a third party, LG Electronics, back in 2021, and were never changed. The age of the login, over three years, didn’t matter. It still worked.
The campaign also highlights cross-organisational trust. A supplier or contractor with access to your systems means your security is only as strong as theirs. Hellcat has also hit telecom firms including Orange and Telefónica, and Schneider Electric, all through stolen credentials. The front door, user authentication, is where determined attackers are focusing.
Why identity attacks are surging
Several factors have converged. First, cloud services and SaaS apps mean a single employee login can be a gateway to a trove of data. Jira holds roadmaps, incident reports, customer information and sometimes secrets pasted into tickets. Gaining a Jira account is almost like getting a skeleton key to the digital office. Attackers quietly impersonate an insider, which evades traditional defences: there is no malware signature and no exploit chain, just an apparently valid user doing apparently normal things.
Second, the underground market for credentials has exploded. Breaches and info-stealer campaigns have dumped billions of username and password pairs online, and many users still reuse passwords across personal and work accounts. The 2024 Verizon Data Breach Investigations Report noted that 77% of web application attacks involved stolen credentials. Attackers follow the path of least resistance, and today that path is often an unguarded login page.
Finally, many organisations have not fully implemented multi-factor authentication or robust identity policies for every application. In several of Hellcat’s cases the Jira login seems to have been protected by a password alone. With MFA enforced, the stolen passwords would likely have been insufficient. With tighter monitoring of login locations and behaviour, anomalous logins from foreign addresses or at odd hours might have raised flags sooner.
Impact: data theft and extortion
Hellcat operated a double extortion model: steal sensitive data, then threaten to publish it unless the victim pays. They reportedly demanded $125,000 from Schneider Electric after stealing 40 GB of data. Even where companies refused to pay, the group dumped portions of data on dark web forums. Exposed data ranged from source code and product plans to personal information on employees and customers, bringing intellectual property loss, regulatory penalties and reputational harm.
The group has also been linked to ransomware encryptors and reportedly offers a ransomware-as-a-service programme. Once an attacker has a foothold through a valid account, they can escalate to whatever endgame they prefer: extortion, sabotage or surveillance.
Defending the front door
For security leaders, Hellcat’s run is a reminder to prioritise identity security. Key steps:
- Enforce multi-factor authentication. For every account, especially remote and cloud access. Modern MFA such as app-based push or FIDO2 keys adds a hurdle most credential thieves cannot clear.
- Adopt zero trust access. A correct password should not mean automatic trust. Use continuous checks and context-based controls, and segment access so one account cannot see or exfiltrate everything.
- Hunt for compromised credentials. Assume some will leak. Monitor for your company’s emails and logins appearing in breach dumps and reset them immediately.
- Improve password hygiene. Enforce strong, unique passwords, rotate privileged credentials, and move to password-less methods where you can. JLR’s static credentials stayed valid for years.
- Limit third-party access. Review which partners and suppliers can reach your systems, require MFA from them, prefer federated access you control, and remove accounts you no longer need.
- Treat SaaS like on-premises. Check configurations, audit logs and permissions, use SSO, and lock down admin accounts.
- Train people to speak up. Make it safe to say “I think my credentials were stolen.” Speed of response matters more than blame.
The bigger picture: identity is cybersecurity
Groups like Hellcat show that the front line has shifted. With cloud adoption the network perimeter is fading and identity has become the new perimeter. Attackers bypass hardened firewalls and endpoint defences by logging in through the front door. Investment in detection can be undermined if the basics of identity and access management are not right.
Cybercriminals also go for the simplest effective tactic. Why spend weeks writing an exploit when a $10 purchase of a leaked password gets you in? Until organisations choke off that supply, by stopping theft and by making stolen credentials useless through MFA and faster resets, the trend will continue.
Strengthening identity defences
Hellcat’s campaign should be a wake-up call. Implement strong authentication, continuous monitoring and zero trust principles, and consider regular simulated identity attacks as part of penetration testing or red team exercises, to see whether a stolen credential could slip past your defences. It is far better for an ethical hacking team to find a lapse in MFA or an overly permissive SaaS account than a real adversary.
These breaches also underline the need for attack surface management that covers exposed cloud apps, credentials and third-party connections, so you are alerted if an admin login is publicly reachable or a partner’s credentials appear in a leak. You may not prevent every credential from leaking, but you can make sure a leaked password does not become a business crisis.
Sources cited in the original: Push Security on Hellcat tactics and breaches; Hudson Rock via SecurityWeek on credential theft; Verizon 2024 DBIR.