Have I Been Pwned reports that German news service NIUS suffered a data breach in July 2025 that was later leaked publicly. The exposed data covers roughly 6,090 unique email addresses paired with names, physical addresses and payment information such as IBANs or partial credit card data (masked card number, type and expiry).
While no passwords were reportedly included, the combination of email addresses, real names, addresses and financial identifiers creates strong material for targeted phishing and social-engineering attacks. Exposed emails and personal details are frequently reused to craft convincing lures that can lead to credential theft and downstream account compromise.
What to take away: Organizations should treat leaked personal data as feedstock for identity-based attacks. Encourage affected users to be alert to targeted phishing, and monitor for exposed corporate email addresses that could be leveraged against enterprise identity systems.