# Council of Europe Faces Major Data Breach: ShinyHunters Claims Theft of 429,000 Documents


The Council of Europe, Europe's oldest and most authoritative human rights institution, is investigating a significant data breach claimed by the notorious ShinyHunters extortion gang. The cybercriminals claim to have exfiltrated over 429,000 documents containing sensitive HR and payroll information from multiple Council departments, with a threatened public release slated for June 16, 2026.


## The Threat: ShinyHunters' Extortion Campaign


Over the weekend of June 14-15, 2026, ShinyHunters posted details of their alleged breach on their dark web leak site, issuing an ultimatum to the Council of Europe. The threat included a stark message: "This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way."


The group's post detailed an extensive data cache allegedly taken from the organization:


  • 409,000+ payslips spanning 15 years (2011-2026) for over 10,000 staff members
  • 3,700+ personnel files containing employment records and sensitive HR documentation
  • 14,000+ CVs of current and former employees
  • Personal and financial data including names, dates of birth, home addresses, phone numbers, and employee IDs
  • Financial information including salaries, bank account details, tax records, and Social Security information
  • Medical records and other sensitive health-related documentation

  • When contacted by cybersecurity news outlet BleepingComputer, a Council of Europe media department representative confirmed the organization is investigating the claims but declined to provide additional details: "We are currently investigating the matter and assessing the situation. We have no further comment to make at this stage."


    ## Background and Context: Who Is the Council of Europe?


    The Council of Europe stands as Europe's pre-eminent human rights organization and the continent's oldest intergovernmental body. Founded in 1949, the organization represents 46 European member states and serves a population exceeding 700 million people. The Council is responsible for promoting democracy, the rule of law, and human rights standards across Europe and beyond.


    The organization's significance makes this breach particularly grave. As a guardian of democratic values and human rights across the continent, any compromise of its internal systems raises questions about the security practices protecting European governance institutions.


    ## The ShinyHunters Pattern: A History of High-Profile Attacks


    ShinyHunters is not a newcomer to cybercrime. The extortion group has established itself as a serious threat to enterprise organizations and large institutions over the past 18 months:


    | Target Category | Number of Breaches | Notable Details |

    |---|---|---|

    | Salesforce Customers | Hundreds | 1.5+ billion records stolen in Aura and Salesloft Drift campaigns |

    | Snowflake Customers | Dozen+ | Widespread campaign exploiting weak credentials |

    | PeopleSoft Systems | 100+ organizations | Exploited zero-day vulnerability discovered last week |

    | Other Targets | Multiple | Including University of Nottingham and various Fortune 500 companies |


    The group's modus operandi typically involves:

  • Identifying vulnerable entry points in widely-used software platforms
  • Exfiltrating large volumes of sensitive data
  • Posting samples on dark web leak sites
  • Demanding payment with threats of public release
  • Following through on threats when demands aren't met

  • ## Technical Details: Scope and Data Classification


    The data allegedly stolen from the Council of Europe represents a comprehensive snapshot of the organization's human resources infrastructure spanning over a decade. The breadth of information is particularly concerning:


    Financial Data: Salary information, bank account details, and payment records for thousands of employees create a high-value target for secondary fraud, blackmail, or identity theft schemes.


    Personal Identifiers: Names, dates of birth, home addresses, and phone numbers provide everything needed for targeted phishing campaigns, social engineering attacks, and physical security threats against employees.


    Health Information: The inclusion of medical records suggests the breach may extend beyond human resources systems into occupational health or benefits administration platforms—areas often subject to stricter data protection requirements under GDPR and other privacy regulations.


    Historical Scope: The 15-year window of payslips indicates that the attacker maintained access to systems for an extended period or accessed historical data archives, suggesting either a sophisticated persistent threat or inadequate data retention controls.


    ## Implications: Risks for Employees and the Organization


    For Individual Employees: Staff members face immediate risks of identity theft, financial fraud, and blackmail. The combination of financial information, medical history, and personal identifiers creates a complete profile for sophisticated threat actors. Social engineering attacks using personal information—including details about family structure, health conditions, or financial circumstances—become far more credible and dangerous.


    For the Council of Europe: The breach impacts the organization's credibility as a guardian of human rights and data protection standards at a time when European institutions face unprecedented scrutiny over cybersecurity practices. The organization must now coordinate notifications to thousands of current and former employees across 46 member states, manage legal obligations under GDPR and national privacy laws, and investigate how attackers accessed such extensive systems.


    For European Governance: As attacks on major institutions intensify, questions arise about the security posture of critical European administrative infrastructure. If the Council of Europe—an institution dedicated to upholding rule of law and human rights—cannot adequately protect its own systems, confidence in European institutions' ability to safeguard sensitive governance data erodes.


    ## Recommendations: Immediate and Long-Term Actions


    Immediate Actions (24-72 hours):

  • Assume the breach is comprehensive and begin notifications to all potentially affected individuals
  • Engage GDPR and national data protection authorities across all member states
  • Activate incident response teams and external forensics firms to determine entry vectors
  • Issue fraud alerts and credit monitoring offers to affected employees
  • Isolate affected systems to prevent further exfiltration

  • Intermediate Actions (1-4 weeks):

  • Conduct comprehensive audit of data access logs and system permissions
  • Implement additional monitoring on financial systems and HR databases
  • Reset credentials for all staff with administrative access
  • Review third-party vendor access to sensitive systems

  • Long-Term Measures (ongoing):

  • Deploy advanced persistent threat (APT) detection capabilities
  • Implement zero-trust security architecture for sensitive data systems
  • Establish data minimization practices to reduce the volume of sensitive information stored
  • Conduct tabletop exercises to improve breach response procedures
  • Increase funding for cybersecurity infrastructure and personnel

  • ---


    ## HackWire Analysis


    The Council of Europe breach represents a escalating pattern in 2026: attackers are moving beyond private companies to target the institutional backbone of democratic governance. ShinyHunters' methodical progression—from SaaS platforms (Salesforce) to cloud data warehouses (Snowflake) to enterprise software (PeopleSoft) to government institutions (Council of Europe)—reveals a deliberate strategy to maximize victim vulnerability and ransom leverage.


    What's particularly striking is the timeline compression. The group's PeopleSoft zero-day campaign affected 100+ organizations last week. The Council of Europe breach claims surfaced days later. This suggests attackers aren't just reacting to discovered vulnerabilities—they're actively hunting for organizations with the worst security practices and the highest ability to pay.


    The inclusion of 15 years of payroll data deserves scrutiny. This isn't a opportunistic grab—it indicates either long-term persistent access (months or years) that nobody detected, or that the Council of Europe stores a decade-plus of sensitive data with minimal access controls. Either scenario is damning for an institution responsible for promoting human rights standards across 700 million people.


    For other European institutions and large organizations: this is a wake-up call that size and prestige offer no protection. The Council's mandate is literally to promote democracy and rule of law. If ShinyHunters can breach them, they can breach anyone. Organizations should assume their own critical systems have already been probed, and begin forensics immediately rather than waiting for a ransom demand.


    The payment deadline (June 16) is already upon us as of publication. Whether the Council pays or refuses, the leaked data will likely surface on dark web forums and breach databases within weeks, making this a permanent compromise of hundreds of thousands of European citizens' personal and financial information.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)