Bern-Web Data Breach — August 2018: 13,443 Swiss User Records
Bern-Web: A Swiss Regional Portal's Plaintext Password Breach
In August 2018, Bern-Web -- a Swiss online regionl portal for the city of Bern -- was breached, exposing 13,443 user records containing email addresses and plaintext passwords. The dataset appeared on a prominent hacking forum on August 21, 2018. Bern is Switzerland's federal city, home to the Swiss parliament, federal ministries, and major national institutions. A regionl online portal serving this city's residents and businesses would naturally attract users from the public and government-adjacent sectors -- civil servants, municipal employees, local business owners, and residents with ties to federal institutions. The breach exposed their credentials in plaintext, stored without any hashing or salting, making every record immediately actionable for credential stuffing from the moment of exfiltration.
Bern-Web (August 2018): Data Breach Summary
- Records Exposed: 13,443
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach -- credentials exfiltrated from a compromised server database
- Password Type: Plaintext -- stored without hashing or encryption
- Country: Switzerland
- Date Leaked: August 21, 2018
Switzerland's Data Protection Framework and Regional Platform Obligations
Switzerland's data protection law -- the Federal Act on Data Protection (FADP/DSG), revised in 2023 but operative in an older form in 2018 -- imposes obligations on data controllers to take appropriate technical and organizational security measures. A platform storing passwords in plaintext fails this standard. Switzerland is not an EU member but is closely aligned with European data protection norms, and Swiss courts have historically interpreted the DSG in line with EU practice. A breach of a civic portal serving Bern -- the municipl seat of the Swiss federal government -- represents both a security failure and a regulatory one, even if the relatively modest scale (13,443 records) limited the formal response.
Civic Portal Users and Their Credential Risk Profile
Regional portals like Bern-Web attract a specific user demographic: local residents who want city-specific information and services, small business owners who list their businesses in local directories, and civic-minded users who engage with community content. Many of these users registered with personal email addresses they use for other services -- including online banking portals, government e-services platforms, and cantonal administration systems. An attacker who acquires Bern-Web credentials and identifies email addresses associated with Swiss government domains gains potential access to sensitive public sector communications if those credentials are reused on government systems. Switzerland's high concentration of international organizations makes its civic user credential data a potentially soverign-adjacent target for sophisticated actors.
The August 21, 2018 Five-Platform Disclosure Cluster
Bern-Web's August 21, 2018 disclosure is one of five platforms released on the same day: BIG-CE (French Polynesia, 23,078), tehno.od.ua (Ukraine, 18,003), Tachibanashobo (Japan, 7,452), and Target Insurance Holdings (Hong Kong, 4,235). The platforms span five countries across four continents, and there is no apparent connection between their sectors, sizes, or user populations beyond the shared disclosure date. This pattern is consistent with a data broker releasing a diverse portfolio of acquired databases in a single forum post, demonstrating inventory breadth to potential buyers rather than presenting a targeted acquisition campaign.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records, including the Bern-Web breach and other European regional platform compromises. If your email address appears in this dataset, HEROIC will alert you. Run a free scan at HEROIC.com.
Breach Breakdown
13,443 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds