Menu
Browse

Cyber Incident Victim: Vorwerk

Date:

Jan 2025

Location:

Germany

Summary

A cyberattack targeting the Rezeptwelt.de forum, associated with Vorwerk's Thermomix community, resulted in the theft of personal data from approximately 3.3 million users. Attackers accessed names, addresses, birthdates, phone numbers, and email addresses through unauthorized entry to an external service provider's subordinate server. While sensitive payment details and passwords were reportedly not compromised, the company acknowledged potential password risks. The breach was isolated to the recipe-sharing platform, with other corporate services unaffected. Following detection, the compromised server was deactivated and the vulnerability patched. The organization issued warnings about phishing risks and is collaborating with authorities to address the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Between January 30 and February 3, 2025, unauthorized actors gained access to a subordinate server managed by an external service provider supporting Rezeptwelt.de, a Thermomix recipe-sharing forum operated by Vorwerk. The attackers exfiltrated user profile data from the platform, compromising information belonging to 3.3 million registered users. The stolen dataset included full names, physical addresses, birthdates, telephone numbers, and email addresses, contingent upon the details voluntarily provided by individual forum members during account creation or profile updates. Forensic analysis confirmed the breach did not involve extraction of sensitive authentication credentials such as passwords or financial payment information, though Vorwerk acknowledged it could not definitively rule out potential password exposure. The intrusion was confined to the Rezeptwelt.de forum infrastructure, with no evidence of compromise affecting Vorwerk's primary commercial platforms like Cookidoo or its corporate webshop.

Cyber Incident Image

Vorwerk's security team disabled the compromised server upon identifying the breach, effectively terminating unauthorized access by February 3. The company subsequently implemented patches to address the vulnerability exploited in the attack and initiated coordination with law enforcement agencies to investigate the incident. Public disclosure occurred after the Spiegel reported the appearance of the stolen dataset in darknet marketplaces, where threat actors advertised it for fraudulent exploitation. Vorwerk issued a formal apology to affected users, advising heightened vigilance against potential phishing attempts leveraging the stolen contact details. The firm directed concerned individuals to contact its data protection officer but did not confirm whether it would provide credit monitoring services or other remediation beyond technical containment. Operational restoration timelines for Rezeptwelt.de remained unspecified in available communications.

Sources
Sources available to members
1 source