Samsung Germany support tickets leaked after four-year-old credentials were reused

Organization
Samsung Germany
Exploit
Credential Compromise
Industry
Technology

In late March 2025 an actor using the handle GHNA published roughly 270,000 customer service tickets taken from Samsung's German operations. The records came from samsung-shop.spectos.com, a ticketing and service quality platform run by Spectos GmbH, a Dresden company contracted by Samsung.

The threat intelligence firm Hudson Rock traced the intrusion to login credentials stolen from a Spectos employee's computer in 2021 by Raccoon infostealer malware. The account was never rotated and the credentials still worked four years later. Hudson Rock said it had catalogued the compromised credentials in its own database long before the data was published.

The tickets contained full names, postal and email addresses, order and transaction details, shipment tracking links, ticket identifiers and the message threads between customers and support agents. Heise reported that most of the material dated from 2025 and that GHNA had offered the collection for about two euros before releasing it.

Researchers noted that the combination of order records and live tracking links made the data unusually well suited to targeted phishing, parcel interception and fraudulent warranty claims. Samsung did not immediately respond to a request from heise online for confirmation of the data leak and the authenticity of the data. Samsung Germany told CSO Online on 2 April 2025 that an incident involving unauthorized access to customer data had occurred on an IT system belonging to one of Samsung's business partners in Germany, and that it was investigating the extent. Spectos published a statement on 1 April 2025 confirming a cyber incident and told Infosecurity the next day that unauthorized access to its systems and personal customer data had occurred. Neither company gave a figure for how many customers it would notify.

Sources