NIUS Data Breach (August 2026)
NIUS, the German online news service, was breached in July 2025 and 6,090 subscriber records were published, including names, email addresses, physical addresses and payment details such as bank account numbers or masked credit card data.
- Organization
- NIUS
- Sector
- Media and entertainment
- Country
- Germany
- Incident date
- July 13, 2025
- Disclosed
- August 23, 2026
- Records affected
- 6,090
- Attack type
- Undisclosed
- Status
- Confirmed
- Bank account numbers
- Email addresses
- Names
- Partial credit card data
- Physical addresses
- Purchases
- Attackers deface nius.de and replace its headlines with a link to a subscriber database, as reported by heise online.
- The incident date recorded for the breach on the Have I Been Pwned listing.
- Have I Been Pwned loads the verified records.
What Happened
The German news service NIUS suffered a data breach in July 2025 that was subsequently leaked publicly, per the Have I Been Pwned entry. Have I Been Pwned verified and loaded 6,090 records containing names, email addresses, physical addresses and payment details, with purchase records carrying either a bank account number in IBAN form or partial credit card data made up of a masked number, the card type and the expiry date.
Dirk Knop reported for heise online on July 13, 2025 that attackers had defaced nius.de the previous day, replacing every headline on the site with a link to a downloadable database. According to that report the published file held roughly 5,700 subscriber records with names, email addresses, pseudonymized card or account details and the subscription type each customer had chosen, alongside credentials for the site's Squidex content management system and its Swagger API documentation.
heise online reported that NIUS had not answered its questions at the time of publication and that the site had begun restoring its headlines without acknowledging the defacement. That report also noted it was not then clear whether the published data was genuine or whether the attackers were internal or external. Have I Been Pwned loaded the verified records on August 23, 2026, more than a year after the file first circulated.
What Was Exposed
6 classes of data across 6,090 records, per Have I Been Pwned: NIUS breach listing: bank account numbers, email addresses, names, partial credit card data, physical addresses and purchases.
Pairing a verified name and home address with a bank account number, or with the card type and expiry sitting behind a masked number, gives an attacker the specific details a subscriber would expect a genuine billing message from NIUS to contain.
What to Do If You Are Affected
The full sequence, and what to do in what order, is in what to do after a data breach.
What Is Not Known Yet
How the attackers reached the customer database has not been established publicly, and no group or individual has been named as responsible. NIUS has not given its own public account of what was taken or of how many subscribers it notified.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.