NIUS Breach: 6,090 Credit Cards & Addresses Exposed (2025)
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type a...
Overview
In July 2025, the German news service NIUS suffered a data breach that was later leaked publicly. The incident compromised 6,090 unique email addresses along with associated personal and financial information. The breach was reported to Have I Been Pwned, allowing affected users to verify their exposure. While the scale is relatively modest compared to mega-breaches, the inclusion of payment details elevates this to a CRITICAL severity rating.
What Was Exposed
The leaked dataset contains three distinct categories of information, each with different risk levels:
- Email addresses and names: These are your digital identifiers. Combined, they enable targeted phishing campaigns where attackers impersonate NIUS or related services.
- Physical addresses: This is permanent personal data that cannot be changed. It creates risks for physical mail fraud and doxxing.
- Payment details: Includes either IBANs or partial credit card data (masked card number, card type, and expiry date). The masked card numbers limit direct fraud, but the expiry date and card type help attackers craft convincing social engineering attempts.
Account Takeover Risks
Your email address is the key to your digital identity. With it, attackers can attempt password resets on other services, especially if you reuse passwords across platforms. The combination of email and personal details from this breach makes phishing emails significantly more convincing - attackers can reference your real name, address, and purchase history with NIUS to appear legitimate.
The IBAN data is particularly concerning. Unlike credit cards, IBANs do not have built-in fraud protections like chargebacks. While IBAN alone does not allow direct account withdrawal in most cases, it enables SEPA direct debit fraud where attackers can initiate pulls from your account under false pretenses.
How to Check If You’re Affected
Visit Have I Been Pwned and enter your email address. The service will immediately indicate whether your data was part of this breach. If you used multiple email addresses with NIUS, check each one.
What to Do Right Now
For your payment methods:
- Contact your bank immediately if your IBAN was exposed. Explain the situation and ask about direct debit protection measures.
- Monitor all bank statements and credit card activity for the next 12 months at minimum.
- If your credit card expiry was exposed alongside other data, remain vigilant for phishing attempts referencing your card details.
For your accounts:
- Change your NIUS password immediately if you still have an account.
- Change passwords on any other services where you used the same password (this is critical - do not skip this step).
- Enable two-factor authentication on your email account, as this is the primary target for account takeover attacks.
For your physical security:
- Be alert for unexpected mail or packages. Attackers with your address may attempt to intercept deliveries or use your address for fraudulent orders.
Security Insight
This breach reveals a troubling pattern for a media organization in Germany, a country with some of the strictest data protection laws in the world under GDPR. The exposure of both IBANs and partial credit card data suggests NIUS was storing payment information beyond the transaction processing window, a practice that contradicts data minimization principles. German companies handling payment data should be operating under PCI DSS compliance frameworks, which mandate strict retention limits and encryption standards. The public leak of data months after the initial July incident also indicates poor incident response coordination and raises questions about their disclosure timeline to affected customers. For a news organization whose credibility depends on public trust, this breach of customer financial data carries reputational damage that may outweigh the relatively small number of affected records.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, ...
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of th...
In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone nu...
In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partia...