The February 2025 Breach: Timeline and Attack Chain
On February 23, 2025, an unknown actor breached an internet-exposed Jira instance at Orange Romania. An infostealer had already pulled valid credentials from a personal device. The instance used local accounts outside Orange’s federated password policies. An outdated Jira version meant MFA wasn’t available on those accounts. The attacker exfiltrated 7 gigabytes across 12,000 files. Orange confirmed the breach on February 24; the archive appeared on breach forums the same day. Constantin mapped each step in the MITRE ATT&CK mapping of the Jira breach (06:26): T1589 (infostealer credential theft), T1078 (valid accounts on an internet-exposed system), T1119 and T1048 (collection and exfiltration).
“At no time were Orange Romania services affected.” — Ioan Constantin
Blast Radius Containment: What the Attackers Could Not Do
The attackers never got past the web interface. No file system access, no RCE, no implants, no persistence, no backdoors. They logged into Jira through the browser and ran API calls to pull data. That was the ceiling.
The Jira instance was isolated from production networks, so lateral movement never happened. They encrypted nothing. As Constantin put it, they inadvertently delivered “a backup of that Jira instance for us online” — read-only exfiltration, with data integrity intact throughout.
What Worked: Cross-Functional Response and Authority Coordination
The initial response took days, not weeks. War rooms pulled together technology, IT, business, information security, legal, and communications — teams that don’t normally share a room. Scope was fixed: isolate, mitigate, communicate. On the technical side that meant mitigation, forensics, and evidence preservation. DNSC and other national authorities stayed close throughout.
The business and communications teams carried the external load, pushing coordinated answers to affected customers asking what data was exposed, to what degree, and who could use it. Crisis management, internal communications, external communications — the processes held. Technical people focused on technical work. Communications people focused on communications.
What Failed: Unenforced Controls and Security Awareness Gaps
Two things failed. The Jira instance was flagged as an exception to existing technical controls, and audits against it were not rigorous. The second failure was comfort with those exception paths. Constantin asked the DefCamp audience to raise their hands if they held local admin rights on company workstations (16:23). About 10% did. Security professionals normalizing exceptions is exactly how a known-bad configuration survives.
“Every lesson that we learn is a catalyst for change.” — Ioan Constantin
Post-Incident Hardening: Technical and Operational Actions
Orange minimized stored data, added anomaly detection on the network layer, and enforced MFA on internal apps that had relied on perimeter trust. PAM controls now track admin access across every platform. WAFs went in front of internet-facing apps. Password policies moved to continuous review. For forensics, Orange isolated the Jira instance, created snapshots for third-party investigators, and ran penetration tests to understand how each CVE could be exploited. The team also built automated data-leak monitoring (23:42) — scanning breach forums continuously for leaked B2B and B2C records so targeted notifications could go out before customers found out elsewhere.
Communication Strategy and Policy-to-Practice Transformation
Orange ran four parallel notification tracks: B2B, B2C (10 million-plus customers), internal staff, and external authorities. CRM tracked every contact. Frontline staff got incident-specific training to answer “what is Jira?” from confused callers. Orange called the regulators first.
Converting policy to practice meant auditing every control, deprecating anything tied to platforms decommissioned since 2015, and setting a minimum security baseline across devices, applications, and users. As Constantin put it:
“you need to stop lowrisk analysis” — Ioan Constantin
Homogeneous risk treatment lets a misconfigured Jira sit exposed for years. Prioritize by impact and budget for the upgrades.
Q&A
considering the amount of personal data that uh orange has such as and that was stolen in this breach such as the state ID, names, phone numbers and so on, why did a company have no threat hunting capabilities and does it have now or will the next breach be um also informed by um uh media person like you said? Orange does have threat hunting capabilities, but the Jira instance was never included in the risk process that determines what gets hunted. ▶ 46:38
Notable Quotes
At no time were Orange Romania services affected. Ioan Constantin · ▶ 5:41
Every lesson that we learn is a catalyst for change Ioan Constantin · ▶ 18:05
security is literally everyone’s job in an enterprise Ioan Constantin · ▶ 44:11
you need to stop lowrisk analysis Ioan Constantin · ▶ 41:06
Key Takeaways
- Isolate internet-exposed tools from your corporate identity and password policies — exceptions become the attack surface.
- Treat every breach as a process stress-test: cross-functional war rooms, evidence preservation, and proactive authority notification before they call you.
- Stop treating risk uniformly across your estate — prioritize controls on high-impact vectors and upgrade critical systems continuously.
About the Speaker
Ioan Constantin
Cyber Security Professional with 18 years’ experience in corporate cyber security with a steadfast focus to Research and Innovation. Speaker and household name to some of the largest International Cyber security happenings. Part of a Development and Innovation Team at Orange, where I define, develop, test and pilot new technologies and services for tomorrow’s Telco-tech use-cases. Active developer and participant in Research and Innovation actions in cyber security and networks and technologies for the future.