Schneider Electric confirmed it was investigating unauthorized access to an internal project-tracking platform in November 2024. The extortion group Hellcat claimed it stole more than 40 GB of compressed data and demanded $125,000 in baguettes; those figures were the group’s claims, not details confirmed in the company’s statement.
What happened at Schneider Electric?
On November 5, 2024, Schneider Electric told The Register that it was investigating unauthorized access to an internal project execution tracking platform hosted in an isolated environment. The company said its global incident response team had been mobilized. Its statement did not confirm the amount of data allegedly taken or the ransom demand. The Register’s November 5 report quoted the company’s statement.
The affected platform was described as an internal project execution system. The available reporting does not establish that industrial control systems or energy delivery were disrupted, so the incident should not be described as an attack that caused power outages or interrupted energy operations.
What did Hellcat claim and demand?
In November 2024, Hellcat claimed it had taken more than 40 GB of compressed data and demanded $125,000 in baguettes, according to The Register. These are claims attributed to the extortion group, not independently verified figures or amounts confirmed by Schneider Electric.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
The Register reported that Schneider Electric declined to say whether the baguettes demand was literal or whether the group would accept cryptocurrency. The reporting does not establish that the demand was intended literally.
What information was later reported leaked?
On January 28, 2025, The Register reported that Hellcat had leaked 75,000 email addresses and full names of Schneider Electric employees and customers. The figure describes what the outlet reported as leaked; it does not confirm that the group’s earlier claim of more than 40 GB was accurate. The Register’s follow-up reported the leak.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What remains unknown?
- The reporting reviewed does not identify how the attackers first gained access or establish the full forensic scope of the incident.
- It does not establish whether Schneider Electric paid the ransom.
- It does not establish that operational technology, industrial control systems, or energy delivery were affected.
The Register described Hellcat’s broader approach as double extortion—stealing files and threatening to disclose or sell information. That general description provides context for the group’s tactics, but is not independent forensic proof of every detail in this Schneider Electric incident. The January 2025 report discusses that pattern.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




