Council of Europe Confirms Investigation into ShinyHunters Data Breach Claims
The Council of Europe, the continent's oldest intergovernmental body and Europe's leading human rights organization, has confirmed it is investigating credible claims of a significant data breach attributed to the notorious ShinyHunters extortion group. The investigation comes after the cybercriminal group posted claims on their dark web leak site over the weekend, alleging they have exfiltrated sensitive HR and payroll data from multiple Council departments.
This incident is part of a broader pattern of cyberattacks targeting international organizations. For context on ShinyHunters' prior attack patterns, see our detailed analysis of the Oracle PeopleSoft RCE vulnerability that the group exploited in attacks against over 100 organizations, including the University of Nottingham.
About the Council of Europe
The Council of Europe represents 46 European member states and a combined population exceeding 700 million people. It serves as the continent's foremost organization promoting democracy, human rights, and the rule of law across Europe and beyond. The organization oversees the European Convention on Human Rights and monitors its implementation through the European Court of Human Rights.
When BleepingComputer reached out for comment on the breach claims, the Council's media department responded: "We are currently investigating the matter and assessing the situation. We have no further comment to make at this stage."
The investigation is ongoing, and the Council has not yet confirmed whether the breach claims are legitimate or disclosed any specific details about the scope of the compromise.
For broader context on how international organizations handle cybersecurity, see our coverage of international data breach notification requirements.
ShinyHunters Claims: 429000 Documents including HR and Payroll Data
According to the ShinyHunters' posting on their dark web leak site, the group claims to have stolen over 429,000 documents containing HR and payroll information. The stolen data allegedly includes:
- Over 409,000 payslips for more than 10,000 staff members, spanning from 2011 to 2026
- Over 3,700 in-house personnel files
- More than 14,000 CVs and resume documents
- Additional confidential files containing sensitive personal information
The ShinyHunters group gave the Council of Europe a final warning, stating: "This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that'll come your way."
The deadline has since passed, raising concerns about whether the data may have been leaked to the public.
ShinyHunters has a history of high-profile breaches including attacks on Salesforce campaigns that allegedly exposed over 1.5 billion records from hundreds of companies worldwide, and Snowflake customer breaches following compromises of SaaS integrators.
What Data May Have Been Compromised
If the breach claims are verified, the stolen data would contain an extensive range of personal and financial information about Council employees, including:
- Full names and employee identification numbers
- Dates of birth and home addresses
- Phone numbers and email addresses
- Salary information and bank account details
- Tax identification numbers and Social Security information
- Medical records and health insurance details
- Performance evaluations and employment history within the Council
This level of personal data exposure would represent a severe violation of GDPR compliance requirements and could have significant legal, financial, and reputational consequences for the Council of Europe. For broader context on data breach compliance, see our comprehensive GDPR compliance guide for organizations.
ShinyHunters: A Prolific Cybercrime Group
ShinyHunters has emerged as one of the most aggressive and successful cyber-extortion groups in recent years. The group claims responsibility for multiple high-profile breaches affecting major technology platforms and organizations:
- Salesforce campaigns: The group claimed to have stolen over 1.5 billion records from hundreds of companies worldwide through attacks on Salesforce Aura and Salesloft Drift campaigns
- Snowflake breaches: ShinyHunters was linked to attacks on over a dozen Snowflake customers after compromising a SaaS integrator
- Oracle PeopleSoft attacks: Last week, the group claimed responsibility for breaches at over 100 organizations, including the University of Nottingham, after exploiting a zero-day vulnerability in Oracle's PeopleSoft enterprise software suite
The group's modus operandi involves threatening to leak stolen data unless their demands are met, often creating significant pressure on targeted organizations to negotiate.
See our detailed investigation of the Oracle PeopleSoft RCE vulnerability CVE-2026-35273 for technical details on the zero-day exploit that enabled their recent attack campaign.
Impact on the Council of Europe
The potential breach at the Council of Europe represents a serious security incident with far-reaching implications:
- Reputational Damage: As Europe's leading human rights organization, the Council's credibility could be severely damaged if it is revealed that inadequate cybersecurity measures allowed such a breach
- Legal and Compliance Issues: The breach could trigger investigations by European data protection authorities and potential GDPR violation fines
- Employee Impact: Thousands of Council employees and their families could face identity theft, financial fraud, and privacy violations
- Political Consequences: The incident could draw attention from national governments and EU institutions, potentially affecting the Council's influence and operations
- Operational Disruption: If ShinyHunters follows through on their threat to create "digital problems," the Council's IT systems could face disruption or ransom demands
The Council has not yet disclosed whether it has engaged external cybersecurity firms to investigate the breach or whether any data has actually been leaked.
Related: How organizations respond to major data breaches and cyber insurance coverage for data breaches.
Recommendations for Affected Individuals
While the Council of Europe investigates, employees whose data may have been compromised should take immediate precautions:
- Monitor Financial Accounts: Check bank statements, credit card statements, and financial accounts for any unauthorized transactions
- Credit Reports: Request free credit reports from major credit bureaus to monitor for identity theft
- Freeze Credit: Consider placing a credit freeze with relevant credit reporting agencies
- Update Passwords: Change passwords for all accounts, especially those using similar credentials to work-related accounts
- Two-Factor Authentication: Enable two-factor authentication on all important accounts
- Phishing Awareness: Remain vigilant for phishing attempts that may use the stolen personal information as bait
- Identity Theft Protection: Consider enrolling in identity theft protection services if offered by the Council
- Document Suspicious Activity: Report any suspicious activity to local law enforcement and relevant authorities
For more information on protecting yourself from identity theft, see our complete personal data security guide.
Ongoing Situation and Next Steps
The situation remains fluid, with several key questions still unanswered:
- Has the Council of Europe confirmed the breach is legitimate?
- What specific systems or databases were compromised?
- Has any data been leaked to the public?
- Is law enforcement involved in the investigation?
- What cybersecurity improvements will the Council implement moving forward?
BleepingComputer will continue to monitor the situation and provide updates as new information becomes available. The Council of Europe has not announced any public statements beyond their initial confirmation that they are investigating the claims.
Related coverage:
- Maine Breach Portal Abused to Publish Fake Data Breach Disclosures
- VRChat Cloud Breach 2026: Fake 24 Million User Report Clarified
- Japanese Energy Giant Kyushu Electric Power Loses Hard Drive With 10.9 Million Customers' Personal Data
- Why Cybercriminal Groups Like ShinyHunters Target International Organizations