2025 Telefónica — internal Jira/ticketing breach (Hellcat); credential-led access; ~2.3GB leak
Data compromised
Internal Jira issue metadata, documents, and employee names/emails enumerated in investigative reporting—customer classes explicitly minimized in corporate statements
Technical writeup
Spain’s Telefónica confirmed to reporters that an internal Jira-style ticketing system saw unauthorized access after criminals leaked samples on cybercrime forums—activity eventually attributed in coverage to the Hellcat cluster. Analysts and press described infostealer-compromised employee credentials, lateral moves toward administrative accounts, and exfiltration on the order of ~2.3 GB of tickets, operational exports, and employee directory-style material. Telefónica publicly stressed residential customers were not impacted while enterprise/Jira contents were investigated.
Root cause
Credential theft (infostealer/social engineering) plus weak segregation on internal developer ticketing infrastructure