← Blog

Council of Europe Investigates ShinyHunters 297 GB Data Theft Claim

Share on X

Breaking: The extortion group ShinyHunters added the Council of Europe to its leak site on June 15, 2026, claiming more than 297 GB of internal data and 429,000+ files exfiltrated from human-resources, Secretariat, Parliamentary Assembly, and medicines-quality directorate systems.

What ShinyHunters claims was stolen

According to SecurityWeek and BleepingComputer reporting on the Tor post, the archive allegedly includes:

  • Payroll exports covering more than 10,000 employees (2011–2026)
  • Over 14,000 CVs, contracts, and purchase orders
  • Absence and illness reports, bank account details, and performance evaluations
  • Employee names, IDs, addresses, phone numbers, dates of birth, tax and social-security data, and medical records

The group threatened to publish the full dataset publicly if the Council did not contact it by June 16 to begin negotiations.

Official response

When SecurityWeek asked for comment, the Council of Europe said it was “investigating the matter and assessing the situation” and had no further statement at that stage. BleepingComputer similarly reported an investigation into ShinyHunters’ claims rather than a confirmed victim count or data categories from the organization itself.

Why this matters

The Council of Europe is a separate institution from the European Union—though 27 EU states are members—and operates as a human-rights and rule-of-law body with observer status at the United Nations. A confirmed HR/payroll compromise would expose diplomats, civil servants, and contractors across 46 member states to identity theft, spear-phishing, and long-tail extortion.

Context: ShinyHunters in 2026

The claim arrives amid the same actor’s Salesforce tenant wave (including Infinite Campus staff data confirmed at 137,100 accounts) and Oracle PeopleSoft zero-day campaigns. Treat actor marketing numbers as unverified until the Council or a regulator publishes notice.

What to do if you work with the Council of Europe

  1. Watch for official breach notifications from Council HR or IT—not leak-site downloads.
  2. Enable MFA on work email and payroll portals; rotate passwords if reused elsewhere.
  3. Expect targeted phishing referencing real job titles or internal project names if samples circulate.

Canonical incident record: Council of Europe 2026 on BreachHistory.

Sources: SecurityWeek, BleepingComputer