Critical

NIUS Breach: 6,090 Credit Cards & Addresses Exposed (2025)

By Yazoul AI · automated

In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type a...

Overview

In July 2025, the German news service NIUS suffered a data breach that was later leaked publicly. The incident compromised 6,090 unique email addresses along with associated personal and financial information. The breach was reported to Have I Been Pwned, allowing affected users to verify their exposure. While the scale is relatively modest compared to mega-breaches, the inclusion of payment details elevates this to a CRITICAL severity rating.

What Was Exposed

The leaked dataset contains three distinct categories of information, each with different risk levels:

  • Email addresses and names: These are your digital identifiers. Combined, they enable targeted phishing campaigns where attackers impersonate NIUS or related services.
  • Physical addresses: This is permanent personal data that cannot be changed. It creates risks for physical mail fraud and doxxing.
  • Payment details: Includes either IBANs or partial credit card data (masked card number, card type, and expiry date). The masked card numbers limit direct fraud, but the expiry date and card type help attackers craft convincing social engineering attempts.

Account Takeover Risks

Your email address is the key to your digital identity. With it, attackers can attempt password resets on other services, especially if you reuse passwords across platforms. The combination of email and personal details from this breach makes phishing emails significantly more convincing - attackers can reference your real name, address, and purchase history with NIUS to appear legitimate.

The IBAN data is particularly concerning. Unlike credit cards, IBANs do not have built-in fraud protections like chargebacks. While IBAN alone does not allow direct account withdrawal in most cases, it enables SEPA direct debit fraud where attackers can initiate pulls from your account under false pretenses.

How to Check If You’re Affected

Visit Have I Been Pwned and enter your email address. The service will immediately indicate whether your data was part of this breach. If you used multiple email addresses with NIUS, check each one.

What to Do Right Now

For your payment methods:

  • Contact your bank immediately if your IBAN was exposed. Explain the situation and ask about direct debit protection measures.
  • Monitor all bank statements and credit card activity for the next 12 months at minimum.
  • If your credit card expiry was exposed alongside other data, remain vigilant for phishing attempts referencing your card details.

For your accounts:

  • Change your NIUS password immediately if you still have an account.
  • Change passwords on any other services where you used the same password (this is critical - do not skip this step).
  • Enable two-factor authentication on your email account, as this is the primary target for account takeover attacks.

For your physical security:

  • Be alert for unexpected mail or packages. Attackers with your address may attempt to intercept deliveries or use your address for fraudulent orders.

Security Insight

This breach reveals a troubling pattern for a media organization in Germany, a country with some of the strictest data protection laws in the world under GDPR. The exposure of both IBANs and partial credit card data suggests NIUS was storing payment information beyond the transaction processing window, a practice that contradicts data minimization principles. German companies handling payment data should be operating under PCI DSS compliance frameworks, which mandate strict retention limits and encryption standards. The public leak of data months after the initial July incident also indicates poor incident response coordination and raises questions about their disclosure timeline to affected customers. For a news organization whose credibility depends on public trust, this breach of customer financial data carries reputational damage that may outweigh the relatively small number of affected records.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.