Hacker Dumps Samsung Support Tickets Online

May 13, 2025

INCIDENT

A cybercriminal offered hundreds of thousands of data records from Samsung Germany on the dark web. The data was copied from Samsung Electronics Germany’s support system by a hacker using the pseudonym “GHNA”. The leaked date sets contain names, addresses, emails, order data, and internal communications. Security specialist Hudson Rock analyzed the breach and found initial access was gained via login credentials stolen by an infostealer in 2021. Raccoon malware harvested login credentials from a third party associated with Samsung’s German ticketing system. These credentials sat dormant until the hacker got their hands on them. And now “270,000 customer tickets have hit the open internet, most of them from 2025, courtesy of a simple login that never got rotated.”

Samsung issued the following statement. “Samsung has been made aware of a data breach impacting one of our system partners in Germany. We take the security of customer data extremely seriously and are working to assess the extent of the incident.”

Incident Date

March 29, 2025

Location

Germany

Estimated Cost


No cost values disclosed.

Victims

Type of Malware

No Malware identified

Threat Source

No threat source identified