2026 Telefónica — Rey/HellCat 106GB internal-data leak claim (unverified; company denies)
Data compromised
Actor-claimed 385,311 files / 106.3GB: internal tickets, emails, purchase orders, partner invoices, logs, customer records, and employee data; actor released ~20K sample files—unverified
Technical writeup
Unverified actor claim — reported June–July 2026. BleepingComputer and Cybernews documented actor Rey (associated with HellCat) threatening to leak 106GB allegedly stolen from Telefónica's internal network, releasing roughly 20,000 sample files and claiming 385,311 files including tickets, emails, invoices, logs, customer records, and employee data. Telefónica told reporters it is an extortion attempt and had not confirmed a new breach at catalog time—distinct from the confirmed January 2025 internal Jira/ticketing incident (telef-nica2025). BreachHistory indexes recordsAffected 0 pending company attestation.
Root cause
Unverified extortion claim by actor Rey (linked to HellCat ransomware) alleging 106GB exfiltration from Telefónica internal network—Telefónica characterized as extortion attempt, distinct from confirmed Jan 2025 Jira breach