CSIDB logo
Incident

Samsung Germany

Incident posture

Attack window
Nov 2025
Location
Germany
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-27 01:44

Linked entities

Victim
Samsung Germany
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Apr 2025
Resolved
Pending

Summary

Samsung Germany reported that approximately 270,000 customer records were taken from its support ticket system after attackers used stolen credentials from a partner company that had been compromised by an infostealer years earlier and never updated. The exposed data includes names, postal addresses, email addresses, order information and internal correspondence, largely reflecting recent customer interactions. The stolen dataset is being offered on a darknet forum for about two euros. Samsung confirmed the incident originated at a business partner’s IT system and said it is investigating the scope.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 1, 2025, heise online reported that approximately 270,000 customer data records from Samsung Germany's support system had been found on the darknet. The data were allegedly exfiltrated from the ticket‑system of Spectos GmbH, which operates the service platform accessible via http://samsung-shop.spectos.com. According to Hudson Rock, the breach originated from login credentials stolen in 2021 by the Raccoon Infostealer from an employee computer of Spectos GmbH. Those credentials, belonging to an administrative account, had not been changed for about four years and were subsequently used to gain unauthorized access to the support database. Hudson Rock identified the compromised credentials in its own leak database and traced the exfiltration to the infostealer activity.

The stolen archive consists mainly of customer satisfaction tickets and includes full names, postal addresses, e‑mail addresses, order details and internal communications. The data predominantly cover interactions from the ongoing year 2025. The user known by the handle "GHNA" offered the dataset in a well‑known underground forum, asking for eight credits, which corresponds to roughly two euros. The forum posting described the material as comprising the aforementioned personal and transactional information, suitable for use in convincing phishing campaigns, fraudulent warranty claims or other offenses that presuppose identity theft. No evidence of alteration or encryption of the data was mentioned in the source.

In response to a request for comment from heise online, Samsung initially did not reply. Later the same day Samsung issued a brief statement acknowledging that an IT system of one of its business partners in Germany had experienced unauthorized access to customer data. The statement emphasized that Samsung takes the security of its customers' data very seriously and that it is currently investigating the extent of the incident. No further technical details, containment measures or timelines were disclosed in the reported statement. The article does not indicate any public remediation actions, notifications to affected individuals or regulatory filings beyond the company's acknowledgment and ongoing investigation.

Sources

Sources available to members: 1 source.

CSIDB