
As early as January 2025, security experts at Mint Secure GmbH discovered a security vulnerability in the test environment of the ‘Delegated User Management (DeBeV)’ system operated by the Federal Office for Migration and Refugees (BAMF). This led to media reports on netzpolitik.org and heise.de.
The focus at the time was on the possibility of taking over user accounts via the ‘Forgotten password’ function, provided the underlying email domain could be registered externally. In February 2026, it became apparent that the underlying risk persists and the application still lacks multi-factor authentication.
The method was also described at the end of 2025 during a talk at the Chaos Computer Club’s 39c3 conference entitled “Lost domains, open doors: what old government domains reveal”.
Background
The original report dated 28 January 2025 explicitly pointed out that the accounts in the test environment included highly privileged users with email addresses from the ‘bamftest.de’ domain.
It was also recommended that:
– All domains in use should be checked to ensure they are actually controlled by the public authority
– Test accounts should be rigorously validated
– Multi-factor authentication should be implemented
– Password reset processes should be made more secure
The domain bamftest.de was also explicitly discussed during a presentation at the Chaos Computer Club’s 39c3 conference.
The domain bamftest.de expired on 11 January 2026. Following the expiry of the Redemption Grace Period (RGP), it became available for registration again on 11 February 2026. The domain was subsequently re-registered by Mint Secure GmbH to prevent potential misuse.

Takeover of an admin account
Subsequently, a password reset was triggered for the following account via the ‘Forgotten password’ function in the test environment (benutzer.test.migra.bamf.de): admin-1@bamftest.de The reset link was successfully received and the password changed. It was then possible to log in to the test environment without multi-factor authentication.

After clicking on the link, a new password could be set. The password change was successful.

This access allowed us to view the user management system once again (several hundred users with first name, surname, email address, telephone number, etc. were visible):

Technical assessment
The incident highlights a structural problem at several levels:
1. Lack of domain monitoring
Accounts remained linked to a domain that was apparently not under the organisation’s permanent control. The domain’s expiry led directly to a real risk of takeover.
2. Unmodified password reset mechanism
The password reset function still allowed for complete account takeover, provided there was access to the email address.
3. No multi-factor authentication
No additional authentication was required, even for an administrative account.
4. Failure to follow up on previous reports
As this very risk had already been highlighted in January 2025, the recurrence of this incident suggests that either:
- A comprehensive risk analysis was not carried out
- The recommended measures were not implemented
- Or processes for the long-term rectification of structural vulnerabilities were lacking
Risk analysis
Even though this once again involved the test environment, the following scenarios are, in principle, conceivable:
- Takeover of privileged accounts
- Access to user and administrative data
- Manipulation of roles and permissions
- Preparation of further attacks
- Damage to reputation and trust
Particularly critical:
this involved an administrative account.
Lessons learnt
This incident highlights a frequently underestimated risk in the field of IT security:
Mint Secure GmbH
Test environments are often treated less strictly from an organisational perspective than production systems. However, as soon as real identities, role models or administrative accounts exist, the same security requirements effectively apply.
Domain ownership, in particular, is an often-overlooked attack vector. Expired domains can lead to complete account takeovers, even without technical exploits in the traditional sense.
Timeline
January 2025: Report of a similar security issue (see netzpolitik.org & heise.de)
11 January 2026: Expiry of the domain ‘bamftest.de’ and start of the 30-day RGP
11 February 2026, 06:55: Registration of the domain ‘bamftest.de’
11 February 2026, approx. 18:30: ‘Forgotten password’ function used for admin-1@bamftest.de (at: benutzer.test.migra.bamf.de) and link received
12 February 2026, approx. 05:23: Reset link used and logged in with the admin-1@bamftest.de account at benutzer.test.migra.bamf.de
12 February 2026, approx. 05:36: Logged out of the account admin-1@bamftest.de
12 February 2026, approx. 06:15: Report sent by email to the official data protection officer, Security@ and CERT-BUND
12 February 2026, 11:06: the BAMF has deactivated the account
12 February 2026, 13:12: the BAMF sends a thank-you email and requests a domain transfer
13 February 2026, midday: the authentication code for the domain bamftest.de is provided and the transfer is successful
How Mint Secure supports you
Effective Vulnerability Management does not end with simply taking note of a report, but only once countermeasures have been verifiably implemented and reviewed.
Vulnerability Management
We identify vulnerabilities such as unused or expiring domains and oversee their verifiable resolution, rather than simply reporting them once.
Security Consulting
We help establish processes to ensure the implementation of findings from previous reports in a sustainable manner.
Penetration Testing
We test password reset mechanisms, MFA coverage and test environments for real-world attack vectors.
Do you operate test or legacy environments using real identities?
We check whether domains, access rights and processes are still under your control.
Conclusion
This latest incident highlights the importance of implementing sustainable measures following security reports.
Technical vulnerabilities can be patched in the short term, whereas organisational weaknesses require structural processes. In this case, the BAMF should respond promptly and strive for continuous improvement.
Mint Secure helps organisations turn a one-off report into sustainable, effective countermeasures.

