A significant data breach has hit Samsung Germany as threat actor “GHNA” has released 270,000 customer support tickets for free on hacking forums.
The breach, which occurred in March 2025, exposes extensive personal and transactional data from Samsung’s German operations dating primarily from 2025.
Cybersecurity experts note this breach wasn’t the result of a sophisticated attack but rather credentials stolen years earlier through infostealer malware.
The incident traces back to 2021 when Raccoon Infostealer malware harvested login credentials from an employee at Spectos GmbH, the company managing Samsung Germany’s ticketing system at samsung-shop.spectos.com.
According to cybercrime intelligence firm Hudson Rock, these compromised credentials remained in their tracking database for years before being exploited.
This breach represents another case of dormant stolen credentials being used long after the initial compromise.
The leaked dataset contains comprehensive customer information, including:
Security researchers highlight multiple exploitation vectors enabled by this breach:
“What makes this leak particularly dangerous is its free availability,” notes the analysis. “Any malicious actor can now orchestrate highly convincing phishing attacks using exact purchase details and order numbers.”
Potential attack scenarios include:
The breach highlights growing concerns about AI’s role in data breach exploitation. Modern language models can rapidly parse unstructured ticket data, extracting actionable information for automated attack campaigns.
The report stated that an AI can convert these 270,000 tickets into clean datasets, identify high-value targets, and generate customized phishing content at scale.
This incident follows similar breaches at Telefonica and Jaguar Land Rover, establishing a pattern of infostealer-enabled attacks. For affected customers, security experts recommend vigilance against suspicious communications referencing their Samsung purchases.
Organizations are advised to implement credential monitoring services and regular rotation of access credentials, particularly for customer data systems.
The breach underscores that sophisticated zero-day exploits aren’t necessary when basic credential hygiene is overlooked.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…