Full Report
A data breach involving Council of Europe was reported in June 2026. See incident details, impact on staff, and recommended security measures.
Analysis Summary
# Incident Report: Council of Europe HR and Payroll Data Extortion
## Executive Summary
In June 2026, the Council of Europe fell victim to a large-scale data exfiltration incident claimed by the extortion group ShinyHunters. The breach resulted in the theft of over 429,000 sensitive documents, including payroll, medical, and financial records for more than 10,000 staff members. The organization is currently investigating the incident while facing threats of a public data leak if extortion demands are not met.
## Incident Details
- **Discovery Date:** June 15, 2026
- **Incident Date:** Ongoing (Records span 2011 to 2026)
- **Affected Organization:** Council of Europe (coe[.]int)
- **Sector:** International Organization / Government
- **Geography:** Europe / International
## Timeline of Events
### Initial Access
- **Date/Time:** Reported June 15, 2026
- **Vector:** Suspected exploitation of cloud environment vulnerabilities or stolen credentials (based on historical threat actor patterns).
- **Details:** Unauthorized access gained to internal repositories and document management systems containing historical HR data.
### Lateral Movement
- Details not fully disclosed, but involved movement from initial entry points to centralized HR and payroll storage systems.
### Data Exfiltration/Impact
- **Data Stolen:** 429,000+ documents; 409,000+ payslips; employee CVs and medical records.
- **Scope:** 10,000+ current and former staff members impacted.
### Detection & Response
- **Discovery:** Triggered by public claims and extortion threats made by the group ShinyHunters.
- **Response Actions:** Council of Europe launched a formal investigation; staff notifications issued regarding identity theft risks.
## Attack Methodology
- **Initial Access:** Stolen credentials or cloud misconfigurations.
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Potential use of stolen credentials for repository access.
- **Discovery:** Target-specific reconnaissance of internal document management systems.
- **Lateral Movement:** Movement within cloud or internal document repositories.
- **Collection:** Gathering of PDFs and document files (payslips, CVs, medical records).
- **Exfiltration:** Transfer of 429,000+ documents to attacker-controlled infrastructure.
- **Impact:** Extortion/Data Ransom (Non-encrypting).
## Impact Assessment
- **Financial:** High risk of fraudulent transactions using stolen bank account details and identity theft.
- **Data Breach:** High; 429,000 documents including PII (Names, DOB, addresses), employee IDs, salaries, and medical history.
- **Operational:** Disruption due to incident response and investigation requirements.
- **Reputational:** Significant; exposure of sensitive data belonging to international diplomats and administrative staff.
## Indicators of Compromise
- **Network indicators:** None disclosed in the initial report.
- **File indicators:** Claims of 429,000+ stolen documents from coe[.]int.
- **Behavioral indicators:** Unusual bulk download activity from internal payroll or HR document repositories.
## Response Actions
- **Containment measures:** Investigation into the source of the leak and securing affected repositories.
- **Eradication steps:** Ongoing investigation into potential backdoors or compromised accounts used by ShinyHunters.
- **Recovery actions:** Advising staff to implement credit freezes and monitor financial statements.
## Lessons Learned
- **Visibility:** Centralized repositories of sensitive historical data (dating back to 2011) require stricter access controls and monitoring.
- **Data Retention:** Storing 15 years of payslips in an accessible online repository increases the "blast radius" of a single credential compromise.
## Recommendations
- **Identity Security:** Implement phishing-resistant Multi-Factor Authentication (MFA) using hardware keys (e.g., FIDO2) across all administrative accounts.
- **Monitoring:** Deploy enhanced Attack Surface Management (ASM) to identify exposed cloud assets or leaked credentials.
- **Data Protection:** Implement Data Loss Prevention (DLP) tools to alert on and block bulk exfiltration of sensitive file types (e.g., payslips, medical records).
- **Staff Protection:** Provide credit monitoring and identity theft protection services to all impacted employees.