Data Breaches

ShinyHunters Claims Council of Europe Hack

The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information.

European Union (EU)

The notorious extortion group ShinyHunters claims to have hacked the Council of Europe and to have stolen nearly 300 gigabytes of data.

Europe’s leading human rights organization and an official United Nations observer, the Council of Europe was founded in 1949 and includes 46 member states, including 27 European Union countries.

On Sunday, ShinyHunters added the Council of Europe to its Tor-based leak site, threatening to release more than 297 GB of data allegedly stolen from the organization’s network.

The hacking group says it exfiltrated over 429,000 files across various departments, including HR, Secretariat, Parliamentary Assembly, and the European Directorate for the Quality of Medicines & HealthCare.

The files allegedly include the payroll data of more than 10,000 Council employees from 2011 to 2026, over 14,000 CVs, contract and purchase order records, absence and illness reports, bank account information, performance evaluations, and payroll exports.

Additionally, the hacking group says the stolen data includes employee names, IDs, addresses, phone numbers, dates of birth, tax and social security information, and medical records.

Advertisement. Scroll to continue reading.

ShinyHunters says it will release the stolen data publicly if the Council of Europe does not contact it by June 16 to begin negotiations.

“We are currently investigating the matter and assessing the situation. We have no further comment to make at this stage,” the Council of Europe said, responding to a SecurityWeek inquiry.

Since mid-2025, the extortion group has been linked to multiple high-profile intrusions, mainly targeting Salesforce customers, including Carnival, Canvas, Grafana, CarGurus, Panera Bread, and other incidents.

Last week, Google confirmed that a new ShinyHunters campaign exploited a zero-day vulnerability in Oracle PeopleSoft, likely impacting 100 organizations.

*Updated with statement from the Council of Europe.

Related: Maine Disables Data Breach Portal Due to Fake Submissions

Related: Iranian Cyber Group Handala Claims Cal Water Hack

Related: 174,000 Impacted by Lansing Community College Data Breach

Related: Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case

Related Content

Data Breaches

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.

Artificial Intelligence

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous...

Artificial Intelligence

Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture”...

Data Breaches

In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version