Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Scania Insurance Portal Breach 2025: How an IT…
Breach analysis Incident: 17 Jun 2025

Scania Insurance Portal Breach 2025: How an IT Partner’s Infostealer-Stolen Login Exposed Claim Documents

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
Category: Human identity
Attack route: Stolen credentials
On this page

On 28 and 29 May 2025, an attacker logged in to insurance.scania.com, an insurance claims application run for Scania Financial Services by an external IT partner, using the credentials of a legitimate external user. Scania said its "current assumption is that the credentials used by the perpetrator were leaked by a password stealer malware." Using that account, the attacker downloaded documents related to insurance claims. Early on 30 May, the attacker emailed several Scania employees from a Proton Mail address threatening to publish the data, and in June a threat actor called "hensi" offered the files for sale on a hacking forum, claiming 34,000 of them. Scania confirmed the incident to BleepingComputer on 17 June, took the application offline, notified privacy authorities and said the impact was limited. Scania is a Swedish maker of heavy trucks, buses and engines and part of the Volkswagen Group.

Key takeaways

  • An attacker used a legitimate external user's credentials to access Scania's insurance claims application on 28 and 29 May 2025.
  • Scania believes the credentials were stolen by infostealer malware; the application is provided by an external IT partner.
  • Insurance claim documents were downloaded and used for extortion; a seller called "hensi" claimed 34,000 files.
  • Scania took the application offline, notified privacy authorities and said the impact was limited.
  • The identity lesson: third-party user accounts on partner-run applications need the same protection as your own, including MFA and monitoring for infostealer exposure.

At a glance

OrganisationScania (Scania Financial Services), part of the Volkswagen Group; an external IT partner provides the affected application
WhenAccess on 28 and 29 May 2025; extortion emails 30 May 2025; confirmed by Scania 17 June 2025
AttackerUnidentified; the data was offered for sale by a threat actor called "hensi"
Entry pointCredentials of a legitimate external user, believed by Scania to have been stolen by infostealer malware
Identities abusedOne external user account on the insurance.scania.com application
ImpactInsurance claim documents downloaded and offered for sale; the attacker claims 34,000 files; Scania says the impact was limited
CategoryHuman identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (infostealer-stolen partner user credentials)

What happened

Threat monitoring platform Hackmanac spotted a forum post in which "hensi" offered data from insurance.scania.com to a single buyer. Cyber Daily quoted the post: "Full attached files is 34,000 and first time hacked + just will 1 hand sell." When BleepingComputer asked Scania about it, the company confirmed: "We can confirm there has been a security related incident in the application "insurance.scania.com", the application is provided by an external IT partner."

Scania explained: "On the 28th and 29th of May, a perpetrator used credentials for a legitimate external user to gain access to a system used for insurance purposes; our current assumption is that the credentials used by the perpetrator were leaked by a password stealer malware." It added: "Using the compromised account, documents related to insurance claims were downloaded." Then came extortion: "Early on the 30th (CEST) the attacker sent emails from proton.me to a number of Scania employees threatening to disclose the data." A second email came from an unrelated third party whose email had been compromised, and "The data was later leaked by an actor named Hensi."

BleepingComputer noted that insurance claim documents are likely to contain personal and possibly financial or medical data, and that the number of people affected was not known. Scania said the breach had limited impact, disabled the application and notified privacy authorities. Check Point Research's weekly report of 23 June summarised the incident as theft "via compromised credentials of an external IT partner."

Timeline

DateEvent
28 May 2025The attacker first logs in to insurance.scania.com with the stolen credentials.
29 May 2025Access continues and claim documents are downloaded.
30 May 2025Extortion emails reach Scania employees.
June 2025"hensi" offers the data for sale; Hackmanac spots the post.
17 June 2025Scania confirms the incident to BleepingComputer.

How it happened: the identity attack path

  1. Credential theft. Infostealer malware captured the login of an external user of the application, according to Scania's assumption.
  2. Login with valid credentials. The attacker signed in to the partner-hosted insurance application as that user.
  3. Data download. Insurance claim documents available to the account were downloaded.
  4. Extortion. Scania employees received threats; the data was offered for sale.
  5. Containment. Scania took the application offline and began an investigation.

Impact

  • Confirmed: insurance claim documents downloaded from insurance.scania.com.
  • Claimed: 34,000 files, according to the seller.
  • Affected people: number not disclosed; claim documents may contain personal, financial or medical data.

What this means for NHI governance

This is a human-identity breach, flagged as such on our breach hub: the account used belonged to a person working for or with an external party. We include it because it shows how third-party access is often the weakest identity in the estate. The application was run by a partner, the user was external, and the credential was stolen from a machine Scania probably did not manage. None of these are unusual.

The controls that would have helped are identity controls: MFA on external user accounts, monitoring infostealer logs for credentials to your own and partner-run applications, and limiting what each external account can download. See our Third-Party Access Guide and MFA Guide.

Recommendations

  • Require MFA for all external users. Stolen passwords alone should not open business applications. See the MFA Guide.
  • Monitor for infostealer-exposed credentials. Check infostealer log sources for credentials to your domains and partner-run applications, and reset them.
  • Govern third-party access. Include partner-hosted applications and their users in access reviews. See the Third-Party Access Guide.
  • Limit bulk downloads. Alert when one account downloads unusual volumes of documents. See the ITDR Guide.
  • Set contractual security expectations. Make MFA and logging requirements part of IT partner contracts.

Frequently asked questions

How was Scania breached?

An attacker used the credentials of a legitimate external user to log in to an insurance claims application on 28 and 29 May 2025. Scania believes the credentials were stolen by infostealer malware.

What data was stolen from Scania?

Documents related to insurance claims. The seller claims 34,000 files. Scania has not said how many people are affected and says the impact was limited.

Why is this listed as a human identity breach?

The account used belonged to an external person, not a service or machine identity, so it is not listed as an NHI breach.

Co-op Cyber Attack 2025 · Zacks Breach Claim 2025 · Third-Party Access Guide · MFA Guide · ITDR Guide

How NHI Mgmt Group can help

Third-party access sits outside most identity programmes. We help teams bring partner users and partner-run applications into scope for MFA, reviews and monitoring. See our NHI and AI agent security training.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org