Dienstleistungen-24 Breach: 31,524 German Classified Ads Accounts Exposed (2017)
German Classified Ads, Fully Exposed: No Encryption, No Excuses
Dienstleistungen-24 (Services-24) was a German-language classified ads platform -- the kind of site where users post service offers, tradespeople advertise availability, and local businesses find contractors. In June 2017, 31,524 user accounts from this platform were exposed with passwords stored in plaintext. For users who registered with their primary email and a reused password, the breach provided attackers with a complete, immediately usable credential pair from a platform that had no business storing passwords in cleartext.
Dienstleistungen-24 (June 2017): Breach Summary
- Records Exposed: 31,524
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach
- Country Affected: Germany
- Date Leaked: June 24, 2017
Classified Ads Platforms and the Professional Services User
Service-oriented classified platforms attract a distinct demographic: freelancers, sole traders, small business owners, and tradespeople who advertise their services to local clients. Many of these users registered with business email addresses and passwords they also used on business banking portals, payroll tools, and client communication platforms. A plaintext breach from a German classified site isn't just exposing one account -- it's exposing a credential set that a working professional likely reused across the platforms they depend on to run their busines.
Germany, GDPR, and the Pre-Regulation Breach Context
The Dienstleistungen-24 breach occurred in June 2017 -- approximately one year before the General Data Protection Regulation came into force across the European Union in May 2018. Under GDPR, a breach of this nature -- plaintext password storage, 31,524 records exposed -- would have triggered mandatory breach notification obligations and potential significant fines. The pre-GDPR timing means no such enforcement action was taken. The contrst highlights the regulatory environment that existed before GDPR: European platforms could store user data in plaintext and face minimal consequence when that data leaked. The breach credentials remained in circulation regardless.
June 2017: Moving Earlier in the Dataset
The Dienstleistungen-24 breach from June 24, 2017 represents one of the earlier entries in the current dataset, predating the December 2017 GameWar breach and the full 2018 cluster by over a year. Its presence in the same aggregated breach markets as the 2018 breaches demonstrates how credential collections accumulate data across multiple years before being packaged and distributed. German-language platforms from 2017 and English-language platforms from 2018 ended up in the same breach pools, reflecting the indiscriminate, cross-regional nature of large-scale credential aggregaton operations.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including classified ads platforms, German business services, and European consumer sites. If you've ever registered on Dienstleistungen-24 or similar platforms, check now to see if your credentials are in breach databases.
Breach Breakdown
31,524 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds