HomeSecurityCouncil of Europe investigates ShinyHunters data breach allegations

Council of Europe investigates ShinyHunters data breach allegations

The Council of Europe is investigating claims by the notorious cyber-extortion group ShinyHuntersthat a huge amount of sensitive data of the organization was accessed.

Council of Europe ShinyHunters for data breach

The Council of Europe, one of the continent's most important institutions in the field of human rights, democracy and the rule of law, represents 46 member states and more than 700 million citizens. For this reason, any potential breach of its information systems assumes particular importance both at a political and technological level.

So far, the agency's competent services have only confirmed that they are investigating the allegations, without releasing further details about the extent or nature of the incident.

What does ShinyHunters support?

According to the group, the data allegedly removed includes more than 409,000 payroll documents relating to over 10,000 employees and covering a period from 2011 to 2026.

At the same time, cybercriminals claim to have gained access to more than 3,700 internal personnel files, over 14,000 resumes and a large number of additional administrative documents.

See also: Chinese hackers stole data from US/Canadian research institutions

If these allegations are confirmed, this would be one of the most serious data breaches linked to a European institutional organization in recent years.

Council of Europe: The data allegedly exposed

The biggest concern is not only the number of files but mainly their content.

According to the information that has been made public, the allegedly stolen data includes personal identification information, dates of birth, home addresses, phone numbers, service IDs, banking information, payroll information, tax data, social security information and possibly employee medical records.

Experts point out that such information is an extremely valuable target for criminal organizations, as it can be used in identity attacks, financial fraud, extortion or targeted phishing campaigns.

Council of Europe investigates ShinyHunters data breach allegations

ShinyHunters and its evolution into a global threat

ShinyHunters is not a new name in the cybercrime scene. In recent years, it has been linked to some of the largest data theft cases worldwide, constantly evolving its techniques and methods of action.

The group has gained a reputation for aggressively exploiting vulnerabilities in cloud services, enterprise platforms, and customer management systems. It also often uses blackmail strategies, threatening to release stolen data if victims do not comply with its demands.

Over the past year, the group has claimed responsibility for attacks that customers Salesforce, claiming to have gained access to more than 1.5 billion records through campaigns that became known as Salesforce Aura and Salesloft Drift.

From Snowflake to Oracle: A Chain of Large-Scale Attacks

ShinyHunters' activities were not limited to just one service ecosystem. The group has also been linked to attacks targeting Snowflake, as well as organizations using various third-party integration and data management providers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Infinite Campus: Data breach affects 137,000 school staff accounts

More recently, cybercriminals have claimed responsibility for a new campaign that has reportedly affected more than 100 organizations internationally. The University of Nottingham.

According to available information, the campaign was based on the exploitation of a zero-day vulnerability in Oracle's PeopleSoft, which highlights how quickly attackers can exploit unknown weaknesses before organizations have time to protect themselves.

Why public organizations are being targeted

Cyberattacks on international organizations have been on the rise in recent years. Attackers know that such organizations handle huge volumes of sensitive information, often originating from many different countries and institutional structures.

Council of Europe investigates ShinyHunters data breach allegations

At the same time, public organizations often have complex digital infrastructures, which can include legacy information systems, multiple levels of access, and thousands of users. This complexity significantly increases the attack surface that cybercriminals can exploit.

Cybersecurity as a strategic priority

Regardless of whether ShinyHunters' claims are fully confirmed or not, the incident serves as a reminder of the importance of cybersecurity for international organizations.

See also: Novo Nordisk: Cyberattack exposed clinical trial data

The protection of personal data, financial information and administrative records is no longer just a technical issue, but a crucial factor in trust and institutional credibility. As cybercrime groups become increasingly organised and technologically advanced, organisations such as the Council of Europe are called upon to invest even more in threat detection, rapid response and protection of critical data.

The investigation is ongoing and the final conclusions are awaited with particular interest by the European cybersecurity community, as they may reveal another important aspect of the actions of one of the most active cyber-extortion groups worldwide.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS