Cyber Security News

Samsung Data Leak – Threat Actors Leak 270,000 Customers Tickets Data

A significant data breach has hit Samsung Germany as threat actor “GHNA” has released 270,000 customer support tickets for free on hacking forums. 

The breach, which occurred in March 2025, exposes extensive personal and transactional data from Samsung’s German operations dating primarily from 2025. 

Cybersecurity experts note this breach wasn’t the result of a sophisticated attack but rather credentials stolen years earlier through infostealer malware.

The incident traces back to 2021 when Raccoon Infostealer malware harvested login credentials from an employee at Spectos GmbH, the company managing Samsung Germany’s ticketing system at samsung-shop.spectos.com. 

According to cybercrime intelligence firm Hudson Rock, these compromised credentials remained in their tracking database for years before being exploited.

This breach represents another case of dormant stolen credentials being used long after the initial compromise.

Threat Actors Leak 270,000 Customers Tickets Data

Samsung Germany Data Breach: Exposed Customer Details

The leaked dataset contains comprehensive customer information, including:

  • Personal identifiable information: Full names, email addresses (e.g., “josi_92@gmx.de”), and complete home addresses (e.g., “Trautenauer Str. 26, 85121 Dachau”)
  • Transaction details: Order numbers (e.g., “DE2213214-32511544”), specific model numbers (e.g., “GU52AU7299UXZG” for a Crystal UHD TV), and payment methods
  • Support interactions: Ticket IDs (e.g., “230406.0095829”), agent emails, and detailed communication logs
  • Tracking information: Active delivery tracking URLs (e.g., “https://myhes.de/de/tracking/xx7932321243293000”)

Security researchers highlight multiple exploitation vectors enabled by this breach:

“What makes this leak particularly dangerous is its free availability,” notes the analysis. “Any malicious actor can now orchestrate highly convincing phishing attacks using exact purchase details and order numbers.”

Potential attack scenarios include:

  • Targeted delivery theft: Using tracking URLs and address information to intercept high-value deliveries.
  • Hyper-personalized phishing: Crafting emails referencing legitimate order numbers (DE321116-32511544) and exact product models.
  • Fraudulent warranty claims: Exploiting order numbers and purchase dates to submit false claims.
  • Support impersonation: Leveraging ticket IDs and agent information to impersonate Samsung support representatives.

The breach highlights growing concerns about AI’s role in data breach exploitation. Modern language models can rapidly parse unstructured ticket data, extracting actionable information for automated attack campaigns.

The report stated that an AI can convert these 270,000 tickets into clean datasets, identify high-value targets, and generate customized phishing content at scale.

This incident follows similar breaches at Telefonica and Jaguar Land Rover, establishing a pattern of infostealer-enabled attacks. For affected customers, security experts recommend vigilance against suspicious communications referencing their Samsung purchases.

Organizations are advised to implement credential monitoring services and regular rotation of access credentials, particularly for customer data systems.

The breach underscores that sophisticated zero-day exploits aren’t necessary when basic credential hygiene is overlooked.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago