2026 Belgian State Security (VSSE) — Ivanti EPMM exploit; employee contact data accessed
Data compromised
Employee names, phone numbers, and email addresses; external contact data may also have been compromised; Ivanti advisories cite possible device identifiers and GPS metadata—classified internal systems reportedly not accessed per RTBF/investigation sources
Technical writeup
June 22, 2026 reporting (Techzine, citing RTBF and sources close to the investigation) disclosed that Belgium’s State Security Service (VSSE / Veiligheid van de Staat) was affected by a cyber incident in which attackers exploited Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities used to manage service phones and access rights. The compromise window ran between May 2025 and spring 2026. An internal investigation found attackers accessed employee personal data including names, phone numbers, and email addresses; external contacts may also have been affected. RTBF and investigative sources said classified data and internal systems processing confidential intelligence remained secure, though contact and location metadata could aid organizational mapping. The same Ivanti EPMM flaws have been linked to incidents at the European Commission, Dutch Judiciary, Dutch Data Protection Authority, and Dutch Correctional Services; CISA previously warned of active exploitation. VSSE had not issued a substantive public response at initial press reporting. BreachHistory indexes recordsAffected 0 pending disclosed headcount.
Root cause
Exploitation of Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities between May 2025 and spring 2026; part of broader EPMM campaign also hitting EU institutions and Dutch agencies