Skip to content
Cyber Security Firms

NIUS Data Breach (August 2026)

NIUS, the German online news service, was breached in July 2025 and 6,090 subscriber records were published, including names, email addresses, physical addresses and payment details such as bank account numbers or masked credit card data.

Disclosed Updated
Organization
NIUS
Country
Germany
Incident date
July 13, 2025
Disclosed
August 23, 2026
Records affected
6,090
Attack type
Undisclosed
Status
Confirmed
Data exposed
  • Bank account numbers
  • Email addresses
  • Names
  • Partial credit card data
  • Physical addresses
  • Purchases
Timeline
  1. Attackers deface nius.de and replace its headlines with a link to a subscriber database, as reported by heise online.
  2. The incident date recorded for the breach on the Have I Been Pwned listing.
  3. Have I Been Pwned loads the verified records.

What Happened

The German news service NIUS suffered a data breach in July 2025 that was subsequently leaked publicly, per the Have I Been Pwned entry. Have I Been Pwned verified and loaded 6,090 records containing names, email addresses, physical addresses and payment details, with purchase records carrying either a bank account number in IBAN form or partial credit card data made up of a masked number, the card type and the expiry date.

Dirk Knop reported for heise online on July 13, 2025 that attackers had defaced nius.de the previous day, replacing every headline on the site with a link to a downloadable database. According to that report the published file held roughly 5,700 subscriber records with names, email addresses, pseudonymized card or account details and the subscription type each customer had chosen, alongside credentials for the site's Squidex content management system and its Swagger API documentation.

heise online reported that NIUS had not answered its questions at the time of publication and that the site had begun restoring its headlines without acknowledging the defacement. That report also noted it was not then clear whether the published data was genuine or whether the attackers were internal or external. Have I Been Pwned loaded the verified records on August 23, 2026, more than a year after the file first circulated.

What Was Exposed

6 classes of data across 6,090 records, per Have I Been Pwned: NIUS breach listing: bank account numbers, email addresses, names, partial credit card data, physical addresses and purchases.

Pairing a verified name and home address with a bank account number, or with the card type and expiry sitting behind a masked number, gives an attacker the specific details a subscriber would expect a genuine billing message from NIUS to contain.

What to Do If You Are Affected

The full sequence, and what to do in what order, is in what to do after a data breach.

What Is Not Known Yet

How the attackers reached the customer database has not been established publicly, and no group or individual has been named as responsible. NIUS has not given its own public account of what was taken or of how many subscribers it notified.

Sources

  1. Have I Been Pwned: NIUS breach listing
  2. heise online, "Cyberangriff auf nius.de: mutmaßlich Nutzerdaten veröffentlicht" by Dirk Knop, July 13, 2025
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →