Skip to main content
Back to overview
High

Samsung Germany Customer Support System Data Leak

In March 2025, approximately 270,000 customer support tickets from Samsung Germany were leaked online by a hacker using the pseudonym "GHNA" on the Darknet platform BreachForums.

Key points

  • In March 2025, approximately 270,000 customer support tickets from Samsung Germany were leaked online by a hacker using the pseudonym "GHNA" on the Darknet platform BreachForums. The incident originated from credentials stolen in 2021 via Raccoon Inf
  • Samsung Germany Customer Support System Data Leak

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Malware · Confidentiality impact

Malware, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality

Published
Jan 1, 2021
Updated
Aug 5, 2026
Confidence
High
Evidence
9 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking, Error activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential extortion or operational risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

SamsungData DisclosureSamsung GermanyGHNADarknetBreachForums. TheRaccoon InfostealerSpectos GmbHSamsungCybersecurity

Quick context

Questions about this signal

What happened in this signal?

In March 2025, approximately 270,000 customer support tickets from Samsung Germany were leaked online by a hacker using the pseudonym "GHNA" on the Darknet platform BreachForums. The incident originated from credentials stolen in 2021 via Raccoon Infostealer malware from an employee of Spectos GmbH, a third-party vendor operating Samsung Germany's customer service ticketing system (samsung-shop.spectos.com). The exposed data included customers' names, addresses, email addresses, order details, purchase records, and internal communications from customer support interactions. Samsung informed affected customers via email of the unauthorized access to their personal data, which covered interactions between November 2021 and March 2025. Cybersecurity firm Hudson Rock had reportedly identified the compromised credentials years prior, indicating a lapse in security hygiene.

When was this signal reported?

Shadow Tier lists Jan 1, 2021 as the signal date.

Which organization is connected to this signal?

Samsung is the organization connected to this public signal.

Explore Samsung
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence