Data Breaches

ShinyHunters Claims Council of Europe Hack

The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.

European Union (EU)

The notorious extortion group ShinyHunters claims to have hacked the Council of Europe and to have stolen nearly 300 gigabytes of data.

Europe’s leading human rights organization and an official United Nations observer, the Council of Europe was founded in 1949 and includes 46 member states, including 27 European Union countries.

On Sunday, ShinyHunters added the Council of Europe to its Tor-based leak site, threatening to release more than 297 GB of data allegedly stolen from the organization’s network.

The hacking group says it exfiltrated over 429,000 files across various departments, including HR, Secretariat, Parliamentary Assembly, and the European Directorate for the Quality of Medicines & HealthCare.

The files allegedly include the payroll data of more than 10,000 Council employees from 2011 to 2026, over 14,000 CVs, contract and purchase order records, absence and illness reports, bank account information, performance evaluations, and payroll exports.

Additionally, the hacking group says the stolen data includes employee names, IDs, addresses, phone numbers, dates of birth, tax and social security information, and medical records.

Advertisement. Scroll to continue reading.

ShinyHunters says it will release the stolen data publicly if the Council of Europe does not contact it by June 16 to begin negotiations.

“We are currently investigating the matter and assessing the situation. We have no further comment to make at this stage,” the Council of Europe said, responding to a SecurityWeek inquiry.

Since mid-2025, the extortion group has been linked to multiple high-profile intrusions, mainly targeting Salesforce customers, including Carnival, Canvas, Grafana, CarGurus, Panera Bread, and other incidents.

Last week, Google confirmed that a new ShinyHunters campaign exploited a zero-day vulnerability in Oracle PeopleSoft, likely impacting 100 organizations.

*Updated with statement from the Council of Europe.

Related: Maine Disables Data Breach Portal Due to Fake Submissions

Related: Iranian Cyber Group Handala Claims Cal Water Hack

Related: 174,000 Impacted by Lansing Community College Data Breach

Related: Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case

Related Content

Artificial Intelligence

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots...

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Data Breaches

The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version