The Dutch Data Protection Authority (DPA) and the Dutch Council of Justice have confirmed that their systems were affected by cyberattacks that exploited recently disclosed vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM).

“ On January 29, the National Cyber Security Center (NCSC) was informed by the vendor about vulnerabilities in EPMM ,” the Dutch authorities said . “ EPMM is used to manage mobile devices, applications and content, including their security .”
See also: Anthropic's DXT has a "critical RCE vulnerability"
“It is now known that data related to the work of AP employees, such as names, business email addresses and phone numbers, has been compromised by unauthorized individuals.“.
Ivanti vulnerabilities: The European Commission is also in the spotlight
The development comes as the European Commission revealed that its central infrastructure for managing mobile devices “detected traces” of a cyberattack, which may have led to access to the names and mobile phone numbers of some of its staff members.
The Commission reported that the incident was contained within nine hours and that no mobile device compromise was detected.
See also: Chinese hackers UNC3886 target Singaporean telecoms

“The Commission takes the security and resilience of its internal systems and data seriously and will continue to monitor the situation,” he added. “It will take all necessary measures to ensure the security of its systems.”
Although the vendor's name was mentioned, no details were shared about how the attackers gained access. It is believed to be linked to malicious activity exploiting vulnerabilities in Ivanti EPMM.
Is Finland also affected?
Finnish information and communications technology provider Valtorialso revealed a breach that exposed details related to the work of up to 50,000 government employees.
See also: Hackers exploit SolarWinds WHD vulnerabilities
The incident, discovered on January 30, 2026, targeted a zero-day vulnerability in the Mobile Device Management Service. The organization said it installed the patch on January 29, 2026, the same day that Ivanti released fixes for CVE-2026-1281 and CVE-2026-1340 (CVSS scores: 9.8). The vulnerabilities could be exploited by an attacker to achieve unauthorized remote code execution.

Ivanti revealed that the vulnerabilities have been exploited as a zero-day. The attacker allegedly gained access to information used to operate the service, including names, business email addresses, phone numbers , and device details.
