← Belgian State Security (VSSE)

2026 Belgian State Security (VSSE) — Ivanti EPMM exploit; employee contact data accessed

2026 Unknown records affected Share on X

Data compromised

Employee names, phone numbers, and email addresses; external contact data may also have been compromised; Ivanti advisories cite possible device identifiers and GPS metadata—classified internal systems reportedly not accessed per RTBF/investigation sources

Technical writeup

June 22, 2026 reporting (Techzine, citing RTBF and sources close to the investigation) disclosed that Belgium’s State Security Service (VSSE / Veiligheid van de Staat) was affected by a cyber incident in which attackers exploited Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities used to manage service phones and access rights. The compromise window ran between May 2025 and spring 2026. An internal investigation found attackers accessed employee personal data including names, phone numbers, and email addresses; external contacts may also have been affected. RTBF and investigative sources said classified data and internal systems processing confidential intelligence remained secure, though contact and location metadata could aid organizational mapping. The same Ivanti EPMM flaws have been linked to incidents at the European Commission, Dutch Judiciary, Dutch Data Protection Authority, and Dutch Correctional Services; CISA previously warned of active exploitation. VSSE had not issued a substantive public response at initial press reporting. BreachHistory indexes recordsAffected 0 pending disclosed headcount.

Root cause

Exploitation of Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities between May 2025 and spring 2026; part of broader EPMM campaign also hitting EU institutions and Dutch agencies

References