// THREAT ACTOR
HELLCAT_
DormantHELLCAT is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of HELLCAT — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 17
- 2024 10
Leak site mirrors
5 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
hellcakbszllztlyqbjzwcbdhfrodx55wq77kmftp4bhnhsnn5r3odad.onionThis Hidden Service Has Been Seized snapshot · 2025-11-19 08:04 -
r7i4vprxr2vznmhnnxj36264ofwx6extopdz535f5v357nqacifymbad.onionIndex of / snapshot · 2024-12-28 21:10 -
hellcat.rwJust a moment... snapshot · 2025-12-23 00:00 -
hcatxn4ppkgmakaatrq6bsbhqk5ouhviygyx57gljjt5iseul5nvpayd.onionHELLCAT | Files snapshot · 2026-06-02 03:35 -
hellcakbszllztlyqbjzwcbdhfrodx55wq77kmftp4bhnhsnn5r3odad.onion404 Not Found snapshot · 2025-11-19 10:01
Recent victims
The 50 most recent victims claimed by HELLCAT. Total in the index: 27.
| Date listed | Victim | Description |
|---|---|---|
| 2025-05-03 | www | wwwwwwwwww |
| 2025-04-19 | test | Today, we have hacked Example Corp, In total, we managed to steal over… |
| 2025-04-10 | Potomac Financial Services | We have breached a U.S.-based financial services firm. 381GB of sensit… |
| 2025-04-07 | P**o*** | We have breached a U.S.-based financial services firm. 381GB of sensit… |
| 2025-04-07 | CVTE | We have breached the internal systems of Guangzhou Shiyuan Electronic … |
| 2025-04-05 | HighWire Press | Jiraware |
| 2025-04-05 | Asseco | Jiraware |
| 2025-04-05 | Racami | Jiraware |
| 2025-04-05 | LeoVegas AB | We have compromised the internal systems of LeoVegas AB. The data in o… |
| 2025-03-29 | Transsion Holdings | We hold almost 70GB of sensitive data from Transsion, a leading mobile… |
| 2025-03-25 | Omnitracs | We hold sensitive files from Omnitracs, a leading provider of fleet ma… |
| 2025-03-24 | Grupo Santillana | We hold sensitive files from Santillana, the largest business unit of … |
| 2025-03-17 | Electronics For Imaging | We hold 19GB of sensitive files from Electronics For Imaging, Inc., in… |
| 2025-03-16 | Ascom Holding AG | 44GB of sensitive data including internal reports, sales documents, co… |
| 2025-02-27 | OneDealer | We have obtained over 330,000 records from OneDealer partners, includi… |
| 2025-02-25 | Groupe Renault | We have successfully extracted 18GB of sensitive data from Groupe Rena… |
| 2025-01-05 | Car Care Plan - Turkey | Car Care Plan is a leading provider of Warranty, Asset Protection, Cos… |
| 2024-12-26 | Car Care Plan - Data Breach | Car Care Plan is a leading provider of Warranty, Asset Protection, Cos… |
| 2024-12-25 | Sistem Informasi Pengelolaan Keuangan Daerah (SIPKD) - Blora Regency | The e-Finance system of Blora Regency, known as the Sistem Informasi P… |
| 2024-11-15 | Pinger - USA | We have successfully breached Pinger’s infrastructure, acquiring 111 G… |
| 2024-11-04 | College of Business - Tanzania | We have successfully accessed and compromised over 500,000 student rec… |
| 2024-11-04 | Ministry of Education - Jordan | We have successfully accessed and compromised a range of sensitive doc… |
| 2024-11-04 | Schneider Electric - France | We have successfully breached Schneider Electric’s infrastructure, acc… |
| 2024-11-04 | Contact us | Do you have any questions? Was your company breached or locked by us? … |
| 2024-10-25 | ??? | ?????????? Wait for us ... #HELLCAT |
| 2024-10-25 | The Knesset - Israel | Using exposed authentication keys, we successfully accessed 45GB of se… |
| 2024-10-25 | Who are we? | We are the #HELLCAT group, a ... Nothing. You can find our PGP key her… |