CSIDB logo
Incident

Tiertafel Werne

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 16:50

Linked entities

Victim
Tiertafel Werne
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Facebook page of a local animal welfare charity was compromised by hackers for approximately five weeks, during which the attackers posted fraudulent donation appeals containing links and replaced the profile picture with an image of actor Tom Selleck. The second chairperson discovered the intrusion after being locked out of the account and warned contacts through a private profile post to ignore the fake appeals, while the organization filed a police report with local law enforcement. A Meta employee also confirmed the account had been hacked through messenger contact. The organization has since regained access to the page, removed the fraudulent posts, and restored the original logo, but is holding off on accepting monetary donations until verifying whether any supporters inadvertently contributed to the scam.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Facebook page of the Tiertafel Werne, a volunteer-run animal welfare organization based in Werne, Germany, was compromised by unauthorized actors, resulting in a roughly five-week period during which the organization's account was under the control of third parties. The incident only became public knowledge after the second chairperson of the association, Jasmin Mühling, disclosed the compromise through her personal Facebook profile in the community group "Weihnachtsengel für 4 Poften." According to her account, she had been unable to log in to the Tiertafel Werne Facebook page for an extended period, during which multiple posts appeared that did not originate from any of the three individuals who normally held access credentials for the account. During the unauthorized access period, the attackers altered the organization's profile picture to a photograph of American actor Tom Selleck, known for his role in the television series "Magnum," a change unrelated to the association's actual mission or branding. The attackers also published a series of posts containing fraudulent donation appeals, some of which included embedded links. Mühling stated that she personally did not open any of the suspicious links but issued warnings to her contacts advising them not to follow the calls to action, recognizing them as likely phishing or scam attempts designed to exploit the trust the public places in the well-known local animal welfare organization.

The fraudulent posts imitated the Tiertafel's typical use of its Facebook presence, which had historically been used to circulate donation appeals and to share information about the association's voluntary work supporting animals in need. The attackers leveraged this established pattern of communication by inserting their own appeals into the same channel, seeking to capitalize on the routine familiarity donors had with receiving such requests from the verified organizational page. The scope of the compromise affected the public-facing Facebook account of the association, though the article does not specify whether any internal systems, email accounts, financial accounts, donor databases, or other digital infrastructure belonging to the Tiertafel Werne were also accessed or impacted during the incident. Mühling indicated that it remained unclear at the time of reporting whether any third parties had responded to the fraudulent appeals and inadvertently made donations to the attackers, leaving an open question regarding financial harm to donors and reputational harm to the organization. The compromised account had approximately five weeks of unauthorized activity before administrative access was restored to the legitimate operators.

In response to the ongoing compromise, Mühling engaged with Meta, the parent company of Facebook, through the platform's Messenger service to report the incident and request intervention. A Meta employee reportedly confirmed through these communications that the account had indeed been targeted by hackers, lending external validation to the association's claims. The organization also filed a formal criminal complaint regarding the hack, which was officially logged by the Polizei Unna, the local police authority with jurisdiction over Werne, on March 23, 2025, according to the police press office. The Polizei Unna maintains public warnings on its website regarding cybercrime broadly, noting that the use of secure passwords incorporating special characters, numbers, and a mix of uppercase and lowercase letters can help protect accounts from unauthorized access, though the article does not specify the cause of the initial compromise, such as credential reuse, phishing of an authorized user, brute force, or platform vulnerability.

By March 25, 2025, the legitimate administrators had regained conditional access to the Facebook page and announced via a post that the organization had returned to the platform "under reservation" ("unter Vorbehalt"). In the same announcement, the Tiertafel Werne requested that members of the public refrain from sending monetary donations to the organization's bank account or PayPal address until a thorough review could be conducted to determine whether any unauthorized transactions or other damage had occurred as a result of the hack. The association indicated that once this internal audit was completed and any potential harm was ruled out, an all-clear notice would be issued to supporters. In the interim, the organization directed donors who wished to contribute to coordinate directly with Mühling, either by telephone at 02389/7786954 or by email at [email protected], in order to ensure that donations reached the legitimate association rather than potentially being intercepted or misdirected through the compromised digital infrastructure.

Following the restoration of access, the Tiertafel Werne took steps to clean up the compromised account by removing the fraudulent posts that had been published by the attackers and restoring the organization's logo as the profile picture, replacing the temporary image of Tom Selleck. These remediation actions signaled the technical end of the unauthorized access period and the beginning of the recovery and assessment phase for the organization. The incident highlighted the vulnerability of small, volunteer-driven nonprofit organizations that rely on social media platforms for outreach and fundraising, as they may have limited resources to dedicate to cybersecurity monitoring and rapid response. The Polizei Unna continues to monitor and publicize cybercriminal activity in its jurisdiction, though the article does not indicate whether further investigative steps have been taken, whether any suspects have been identified, or whether the perpetrators have been apprehended. The Tiertafel Werne's experience serves as a documented case of social media account hijacking used to distribute fraudulent donation appeals, with the potential downstream consequences to both the organization's reputation and to unsuspecting donors who may have encountered the compromised page during the five-week window.

Sources

Sources available to members: 1 source.

CSIDB