Breach Intelligence Report 26 Sep 2025

Bern-Web Data Breach — August 2018: 13,443 Swiss User Records

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 13,443
Source Type Database,Combolist
Origin Darkweb
Password Type Plaintext

Bern-Web: A Swiss Regional Portal's Plaintext Password Breach

In August 2018, Bern-Web -- a Swiss online regionl portal for the city of Bern -- was breached, exposing 13,443 user records containing email addresses and plaintext passwords. The dataset appeared on a prominent hacking forum on August 21, 2018. Bern is Switzerland's federal city, home to the Swiss parliament, federal ministries, and major national institutions. A regionl online portal serving this city's residents and businesses would naturally attract users from the public and government-adjacent sectors -- civil servants, municipal employees, local business owners, and residents with ties to federal institutions. The breach exposed their credentials in plaintext, stored without any hashing or salting, making every record immediately actionable for credential stuffing from the moment of exfiltration.


Bern-Web (August 2018): Data Breach Summary

  • Records Exposed: 13,443
  • Data Types: Email addresses, plaintext passwords
  • Breach Type: Database breach -- credentials exfiltrated from a compromised server database
  • Password Type: Plaintext -- stored without hashing or encryption
  • Country: Switzerland
  • Date Leaked: August 21, 2018

Switzerland's Data Protection Framework and Regional Platform Obligations

Switzerland's data protection law -- the Federal Act on Data Protection (FADP/DSG), revised in 2023 but operative in an older form in 2018 -- imposes obligations on data controllers to take appropriate technical and organizational security measures. A platform storing passwords in plaintext fails this standard. Switzerland is not an EU member but is closely aligned with European data protection norms, and Swiss courts have historically interpreted the DSG in line with EU practice. A breach of a civic portal serving Bern -- the municipl seat of the Swiss federal government -- represents both a security failure and a regulatory one, even if the relatively modest scale (13,443 records) limited the formal response.


Civic Portal Users and Their Credential Risk Profile

Regional portals like Bern-Web attract a specific user demographic: local residents who want city-specific information and services, small business owners who list their businesses in local directories, and civic-minded users who engage with community content. Many of these users registered with personal email addresses they use for other services -- including online banking portals, government e-services platforms, and cantonal administration systems. An attacker who acquires Bern-Web credentials and identifies email addresses associated with Swiss government domains gains potential access to sensitive public sector communications if those credentials are reused on government systems. Switzerland's high concentration of international organizations makes its civic user credential data a potentially soverign-adjacent target for sophisticated actors.


The August 21, 2018 Five-Platform Disclosure Cluster

Bern-Web's August 21, 2018 disclosure is one of five platforms released on the same day: BIG-CE (French Polynesia, 23,078), tehno.od.ua (Ukraine, 18,003), Tachibanashobo (Japan, 7,452), and Target Insurance Holdings (Hong Kong, 4,235). The platforms span five countries across four continents, and there is no apparent connection between their sectors, sizes, or user populations beyond the shared disclosure date. This pattern is consistent with a data broker releasing a diverse portfolio of acquired databases in a single forum post, demonstrating inventory breadth to potential buyers rather than presenting a targeted acquisition campaign.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records, including the Bern-Web breach and other European regional platform compromises. If your email address appears in this dataset, HEROIC will alert you. Run a free scan at HEROIC.com.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Plaintext Password
Password Types Plaintext
Date Leaked 26 Sep 2025
Check in 5 seconds

13,443 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,693 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $97.3K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance