The European Central Bank (ECB), the organization that administers the monetary policy of the Eurozone, announced on Thursday that it had suffered a data breach in which some contact information was stolen.
According to a statement published on its website, the ECB became aware of the incident after the attackers sent a blackmail email “seeking financial compensation for the data.” The cybercriminals supposedly gained access to a database that’s used to store registration data for conferences and visits. While most of the data is encrypted, email addresses, phone numbers and street addresses are not, the ECB said. Data on downloads from the ECB website is also included in the database, but was also encrypted.
Since the breached database is physically separate from internal systems, the organization is confident that market sensitive data has not been compromised.
“The ECB is contacting people whose email addresses or other data might have been compromised and all passwords have been changed on the system as a precaution,” the organization stated. “The ECB takes data security extremely seriously. German police have been informed of the theft and an investigation has started.”
The vulnerability leveraged by the attackers to gain unauthorized access to the website has been patched, the ECB said.
The Associated Press reported that roughly 20,000 email addresses were obtained by the attackers, but the number of compromised phone numbers and street addresses is smaller.

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Critical Baicells Device Vulnerability Can Expose Telecoms Networks to Snooping
- SecurityWeek Analysis: Over 450 Cybersecurity M&A Deals Announced in 2022
- VMware ESXi Servers Targeted in Ransomware Attack via Old Vulnerability
- High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation
- GoAnywhere MFT Users Warned of Zero-Day Exploit
- UK Car Retailer Arnold Clark Hit by Ransomware
- EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft
- Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking
Latest News
- Comcast Wants a Slice of the Enterprise Cybersecurity Business
- Critical Baicells Device Vulnerability Can Expose Telecoms Networks to Snooping
- New York Attorney General Fines Vendor for Illegally Promoting Spyware
- SecurityWeek Analysis: Over 450 Cybersecurity M&A Deals Announced in 2022
- 20 Million Users Impacted by Data Breach at Instant Checkmate, TruthFinder
- Cyber Insights 2023 | Zero Trust and Identity and Access Management
- Cyber Insights 2023 | The Coming of Web3
- European Police Arrest 42 After Cracking Covert App
