16 million online accounts in Germany 'compromised'

Keyboard
BSI haven't disclosed the source of the attack

The Federal Office for Online Security (BSI), Germany's internet security agency, has said that millions of Germans have had their usernames and passwords stolen.

The agency added that up to 16 million Germans may have been affected, according to information forwarded to them by law enforcement agencies and research teams. Many of the targeted computers, BSI says, will likely have malware infecting their systems.

The organisation notes on its webpage that the breach itself was discovered during indepth research analysis of botnets.

A section of the BSI website was set up for German residents to check whether they had been compromised by the breach, but crashed from traffic overload almost immediately after its launch. Users who submit their emails to the website are sent follow-up emails if their accounts have been infected.

Accounts that had been compromised were from websites that used email addresses as usernames, including social media and online shopping sites. Half of those that had been compromised were DE top level domains, meaning that they are likely to have been registered in Germany.

A developing threat

BSI has so far declined to comment on who or what was the source of the hacking, or on details of how the breach had been discovered.

The German hack comes shortly after US retail giant Target found out that it had been compromised in what is the second largest data breach in American history, with 40 million credit and debit card details stolen.

German Social Democrat Party digital affairs officer Lars Klingbeil called for more investment in security research in the wake of the BSI revelation: "This case shows how the issue of online identity theft has developed, and that we probably have a lot to do in the future," he said to newspaper Tagesspiegel.

Despite the hack being disclosed publicly this week, the Mittledeutsche Zeitung newspaper reported that BSI had been aware of it since December.

TOPICS
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Toni Collette in Hereditary
Everything leaving Netflix in April 2025 – from the scariest movie ever made to a beloved DreamWorks animation with 99% on Rotten Tomatoes
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Close up of Leica M11-P viewfinder
I wince at the prospect of the rumored Leica M11-V – here's why