Orange confirms it suffered breach after hacker leaks company documents

An abstract image of digital security.
(Image credit: Shutterstock) (Image credit: Shutterstock)

  • A hacker named Rey exfiltrated tens of thousands of records from Orange Romania
  • They demanded payment, but Orange refused
  • The company is now investigating claims of data theft

Orange Group has confirmed suffering a cyberattack recently, but has said it is still looking into claims of valuable data was stolen.

A member of the HellCat ransomware organization, alias Rey, held access to a “non-critical application”, belonging to Orange Romania, the company’s local branch. They obtained the access by exploiting compromised credentials and flaws in Jira.

The hacker recently started exfiltrating data from the app, and later told BleepingComputer they pulled 380,000 unique email addresses, source code, invoices, contracts, and customer and employee information. In total, they grabbed some 12,000 files, weighing roughly 6.5GB, and while this wasn’t a ransomware operation, the hacker did leave a ransom note and did try to extort the company for money. Orange, however, did not initiate any negotiations, prompting the attacker to release the data on the dark web.

Confirming the attack

Soon after, Orange confirmed it did suffer a cyberattack and that it was looking into the matter.

"Orange can confirm that our operations in Romania have been the target of a cyberattack," a company representative said. "We took immediate action, and our top priority remains protecting the data and interests of our employees, customers and partners. There has been no impact on customers’ operations, and the breach was found to occur on a non-critical back office application.”

The publication also analyzed a data sample and said that, while verified, it was “quite old”.

Some email addresses were used by individuals that worked, or collaborated with, Orange Romania, more than half a decade ago. Other names and email addresses belonged to Yoxo customers, Orange’s subscription service with no contract period, meaning it is difficult to determine if the data is still valid, or not.

Some of the partial payment card information found had expired long ago, BleepingComputer added.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
ID theft
Hackers claim Orange attack, threaten to leak 1TB of data
Telefonica
Telefónica says it was hit by systems breach, internal data leaked online
Oracle
Oracle denies data breach after hacker claims to hold six million records
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
HPE
HPE investigating claims that hacker breached developer environments, source code
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025