SCHUFA records surface on underground forums: alleged 70 million German credit files offered for sale
Threat intelligence firm SOCRadar reported this month that an actor on an underground forum was advertising an alleged database from SCHUFA, Germany's dominant credit bureau, containing roughly 70 million records (SOCRadar blog). The listing was detected on August 17, 2026 and, according to the description circulating on the forum, includes names, dates of birth, addresses, credit scores, payment histories, bank names and IBANs.
What the seller claims
The advertised dataset reads like a near-complete financial identity kit for a large share of Germany's adult population. Credit scores and payment histories are exactly the fields a fraudster needs to pass account-opening checks, apply for loans in a victim's name, or craft convincing phishing and extortion letters that quote real debts back at their targets. The inclusion of IBANs alongside personal identifiers would raise the stakes further, enabling direct debit abuse and highly targeted social engineering. It bears repeating that these claims are unverified. No sample has been independently confirmed as genuine SCHUFA data, and underground sellers routinely repackage old breach material, scraped marketing data or outright fabrications under the name of a well-known institution to inflate prices. Until German authorities or the company itself confirm a compromise, the listing should be treated as an allegation, not an established fact. The pattern is familiar to anyone tracking data markets: a headline-grabbing claim first, verification much later if ever. The shadow database backdrop
Timing gives the story its edge. On July 15, 2026, investigative reporting by NDR and Süddeutsche Zeitung revealed that SCHUFA had been secretly storing historical data on around 68 million consumers beyond the deadlines at which GDPR required deletion, effectively maintaining a shadow database alongside its official scoring records (Tagesschau). Under the GDPR's storage limitation principle, personal data must not be kept longer than necessary; the reporting suggested millions of files lingered for years after they legally should have been purged. The Hessian commissioner for data protection has maintained an open investigation into the bureau since spring 2025, predating the public revelations. That means the company was already under regulatory scrutiny over its retention practices when the alleged sale surfaced. Analysts following the story have noted the uncomfortable sequence: first the company admits internally to holding more than it should, then someone claims to be selling precisely such historical depth on a criminal forum (banking.vision). European PII as dark-web commodity
The listing fits a broader shift in underground economics. American Social Security numbers were long the default currency of identity markets, but European datasets have become increasingly attractive as buyers diversify. A German record with a score history is arguably richer than an SSN lookup: it bundles identity, banking coordinates and behavioral financial data in one row. For sellers, national credit bureaus carry brand recognition that commands premium pricing regardless of whether the goods are real. We have tracked this commodification before, from broker services selling Americans' core identifiers to stealer logs feeding fresh European banking credentials into automated shops. The SSNDOB takedown showed how a mundane-looking lookup service can quietly power years of downstream fraud across an entire country; see our coverage of the SSNDOB data broker seizure for that precedent. GDPR-era tension
There is an irony here that regulators will not miss. Europe's strictest privacy framework was supposed to make this kind of mega-database impossible: minimization, purpose limitation and mandatory deletion windows were designed precisely so that no single entity could lose 70 million Europeans' financial histories at once. Yet the shadow database reporting suggests the opposite incentive operated in practice, with data retained because it might someday prove useful. If the advertised data proves authentic, the question becomes where it leaked from: a direct intrusion, an insider, a partner with legitimate API access, or simply old archives that should never have existed. Each answer carries different consequences, but all of them point back to retention. Data that was deleted on schedule cannot be sold on a forum. If the claim dissolves instead, the episode still functions as a stress test of public trust. Consumers cannot verify what a bureau holds about them, and every unverified sale claim forces institutions to respond under uncertainty while regulators weigh enforcement. What happens next
Watch for three signals in the coming weeks. First, whether SCHUFA or the Hessian regulator issues a statement confirming or denying a breach; silence itself will be read as data. Second, whether credible samples emerge from journalists or researchers able to validate records against willing participants. Third, whether the investigation opened in spring 2025 expands from retention practices to information security. For consumers, practical exposure does not depend on the listing being genuine. IBAN-based fraud attempts and phishing quoting accurate-sounding debt details are cheap to run either way, so treating unexpected payment demands and credit offers with suspicion remains the sensible baseline. The larger lesson sits with institutions: in an era when a single mislaid archive can become a dark-web commodity overnight, the cheapest security control available is deleting data you no longer have a legal right to hold.