Council of Europe investigates ShinyHunters data breach claims

Council of Europe investigates ShinyHunters data breach claims β€” Cybersecurity | Versia.media

The Council of Europe, recognized as the continent's oldest intergovernmental institution, is investigating allegations of a data breach raised by the ShinyHunters extortion group over the weekend.

As Europe's foremost human rights organization, the Council comprises 46 European member states and represents over 700 million people, working to uphold democracy and the rule of law across Europe and beyond.

When approached to verify the cybercrime group's assertions, the Council of Europe's media department informed BleepingComputer that the body is examining the situation and could not offer additional details.

"We are currently investigating the matter and assessing the situation. We have no further comment to make at this stage," the Council stated.

In a post published on their dark web leak site over the weekend, ShinyHunters claimed to have exfiltrated more than 429,000 documents containing HR and payroll data from multiple Council of Europe departments, threatening to release the allegedly stolen files on Tuesday.

"This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way," they said.

ShinyHunters added that the purportedly stolen documents include over 409,000 payslips for more than 10,000 staff members (spanning from 2011 to 2026), more than 3,700 internal personnel files, over 14,000 CVs, and other records.

The stolen files are believed to contain a broad array of personal and financial data, including affected individuals' names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, tax and Social Security information, medical records, and more.

Over the past year, ShinyHunters has also claimed attacks targeting Salesforce customers, stating they have stolen more than 1.5 billion records in breaches affecting hundreds of companies and organizations worldwide in Salesforce Aura and Salesloft Drift campaigns.

They have also been connected to high-profile attacks against over a dozen Snowflake customers and other third-party integration providers.

More recently, last week, the extortion group additionally claimed responsibility for a new data theft campaign that resulted in breaches at over 100 organizations (including the University of Nottingham) after exploiting a zero-day vulnerability in Oracle's PeopleSoft enterprise business software suite.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Related Articles:

Infinite Campus data breach affects 137,000 school staff accounts

Carnival Cruise confirms data breach affecting nearly 6 million people

7-Eleven data breach exposes personal information of 185,000 people

7-Eleven confirms data breach claimed by the ShinyHunters gang

Instructure reaches 'agreement' with ShinyHunters to stop data leak

← Cybersecurity