XOOMAR
Cybersecurity investigators examine encrypted files near a European institution under a dark digital threat.
CybersecurityJune 15, 2026· 5 min read· By XOOMAR Insights Team

ShinyHunters Breach Claim Jolts Council of Europe

Share
Updated on June 15, 2026

More than 429,000 documents may have been stolen from the Council of Europe, according to claims by the ShinyHunters extortion group, putting a possible Council of Europe ShinyHunters data breach under urgent review.

XOOMAR Intelligence

Analyst Take

60/ 100
Moderate
4 sources analyzedLow confidenceTrend20Freshness94Source Trust88Factual Grounding92Signal Cluster20

The Council of Europe told BleepingComputer it is investigating the claims but has not confirmed that its systems were breached or that any stolen data is authentic. That distinction matters. Right now, this is an extortion claim under investigation, not a verified breach.

"We are currently investigating the matter and assessing the situation. We have no further comment to make at this stage," the Council said.

Council of Europe probes ShinyHunters breach claim after weekend extortion post

The Council of Europe, described by BleepingComputer as the continent's oldest intergovernmental body, represents 46 European member states and a population of more than 700 million people. Its work centers on human rights, democracy, and the rule of law.

ShinyHunters posted the claim on its dark web leak site over the weekend. The group alleged it had taken HR and payroll material from multiple Council of Europe departments and threatened to leak the files on Tuesday if the organization did not respond by 16 June 2026.

The group claimed the haul includes:

  • 409,000+ payslips: Covering 10,000+ staff from 2011 to 2026
  • 3,700+ in-house personnel files: Allegedly tied to internal employee records
  • 14,000+ CVs: Potentially exposing recruitment and professional history data
  • Other files: Claimed to include personal, financial, tax, social security, and medical information

SecurityWeek separately reported that ShinyHunters claimed the alleged dataset totals more than 297 GB and spans departments including HR, Secretariat, Parliamentary Assembly, and the European Directorate for the Quality of Medicines & HealthCare.

None of that has been publicly verified by the Council of Europe. The only confirmed fact from the organization is that it is investigating and assessing the situation.


ShinyHunters claim raises pressure to verify payroll and HR data

The pressure point in the alleged Council of Europe ShinyHunters data breach is not just file volume. It is the type of information ShinyHunters says it has.

If the files are authentic, payslips, personnel records, CVs, bank account details, tax data, social security information, and medical records would create immediate privacy and fraud risks for affected individuals. HR data is useful to criminals because it combines identity, employment, financial, and internal organizational context in one place.

ShinyHunters also claimed the stolen material includes names, dates of birth, home addresses, phone numbers, employee IDs, salaries, and bank details. That would make the alleged cache valuable for targeted phishing and impersonation if confirmed.

But extortion groups have every incentive to inflate claims. They can exaggerate file counts, mix old and current data, recycle third-party records, or present partial access as full compromise. Investigators will need to test whether the files are real Council of Europe material, whether they are current, and whether they came from internal systems.

ShinyHunters has a history of public leak pressure campaigns. BleepingComputer reported that the group has claimed attacks against Salesforce customers, alleging more than 1.5 billion records stolen in breaches affecting hundreds of companies and organizations through Salesforce Aura and Salesloft Drift campaigns.

The group was also linked to attacks against over a dozen Snowflake customers and other third-party integration providers. More recently, it claimed responsibility for a data theft campaign tied to a zero-day vulnerability in Oracle PeopleSoft. For related XOOMAR coverage of that thread, see No Patch Yet as PeopleSoft Zero-Day Opens RCE Door and 100 Firms Hit as Oracle Leaves PeopleSoft Unpatched.

Investigators now have to separate proof from pressure

The Council's immediate task is verification. That means checking whether ShinyHunters has authentic samples, matching document metadata and timestamps, reviewing access logs, and identifying whether any employee accounts, HR systems, payroll exports, endpoints, or cloud services were accessed.

The hardest question is source. A real-looking file does not automatically prove a fresh breach of the Council of Europe network. It could be current internal data, old archived material, third-party data, fabricated material, or files obtained through another compromise.

That is why public confirmation may take time. A rushed statement could understate exposure or validate an attacker narrative before the evidence supports it.

A practical comparison:

Claim area ShinyHunters says Confirmed by Council of Europe
Documents stolen 429,000+ No
Payslips 409,000+ No
Staff affected 10,000+ No
CVs 14,000+ No
Investigation underway Not applicable Yes
Public breach confirmation Claimed by attacker No

The strongest signal so far is the Council's acknowledgement that it is investigating. The weakest signal is the attacker's own deadline, because leak-site countdowns are part of the pressure tactic.


The next signal is whether ShinyHunters leaks samples or the Council confirms exposure

The next phase of the Council of Europe ShinyHunters data breach story will turn on evidence. Readers should watch for a formal Council incident statement, confirmation that personal data was exposed, visible leak activity from ShinyHunters, service disruptions, password reset notices, or law enforcement involvement.

If the Council confirms exposure, the focus shifts to affected people and the exact data fields involved. If investigators find the claim is exaggerated or based on stale material, the incident still shows how quickly a leak-site post can force a major institution into public incident-response mode.

For now, the responsible reading is narrow: ShinyHunters claims a large Council of Europe data theft, the Council is investigating, and no public confirmation of a breach has been issued. The watch item is whether the attacker produces verifiable data or the Council confirms that internal systems were accessed.

Impact Analysis

  • The claims involve sensitive HR, payroll, tax, social security, and medical data that could expose employees to fraud or harassment.
  • The Council of Europe has not verified the breach, so readers should distinguish confirmed facts from extortion-group allegations.
  • If authentic, the alleged theft could affect staff across a major European human rights and democracy institution.

Claimed Council of Europe Data Types

Payslips
documents409,000
Personnel files
documents3,700
CVs
documents14,000
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

ShinyHunters Dumps 1.6 Million Records in RingCentral Shakedown

Extortion gang ShinyHunters dumped 280GB of sensitive customer data after RingCentral refused their ransom demand, exposing 1.6 million people to targeted phish

Aug 16, 20267 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Ceva Logistics Hack Exposes Millions of Customer Data Records

A cyberattack on global shipper Ceva Logistics has compromised customer name, address, and contact data, rippling out to major clients including banks, luxury r

Aug 10, 20266 min
Close-up of a man with glasses and binary code projection, symbolizing cyber security.Cybersecurity

Insider Demands $7,540 For Cache Of Corporate Secrets

A data analyst contractor was sentenced to two years in prison for stealing employee data and trying to extort $2.5 million, but the company paid just $7,540 to

Aug 14, 20267 min
A fractured digital shield leaking ultraviolet and infrared light on a dark circuit board, symbolizing compromised data security.Cybersecurity

IDScan Breach Spills Infrared ID Security Images to Dark Web

IDScan.net, a major ID verification vendor, leaked infrared and UV security images from over 153 million driver's licenses, turning anti-fraud tools into a weap

Sep 4, 20267 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Ransomware Gang Hacks ATF Investigation Database

The ransomware gang Qilin claims it hacked an ATF system containing information on investigation targets, forcing the agency to declare a major incident.

Aug 27, 20265 min
A dynamic forex trading floor scene showing intense focus on a glowing EUR/USD chart at a critical technical level.Trading

Euro Hits Multi-Year Wall in ECB Showdown

The euro's rally hit a brick wall at the 200-day moving average, setting up a decisive showdown with Thursday's European Central Bank monetary policy meeting.

Sep 9, 20266 min
A futuristic AI interface in a sleek supermarket hub, visualizing chat prompts being translated dynamically into a digital grocery cart.Technology

Instacart Ends Grocery Scrolling With AI Concierge Clementine

Instacart released Clementine, an AI assistant that turns casual chat prompts like 'kid lunches for a week' into a fully built, ready-to-checkout grocery order.

Sep 9, 20268 min
Hurricane winds and torrential rain batter tropical coastline, illustrating infrastructure vulnerability during extreme weather events.Global Trends

Hurricane Lowell Cuts Power to 30,000 on Kauai

Hurricane Lowell's offshore winds knocked out power for 30,000 residents on Kauai, showcasing how vulnerable critical infrastructure is even without a direct la

Sep 9, 20268 min
Aerial view of hurricane aftermath on tropical island coastline with scattered debris and flooded infrastructure under dramatic skies.Global Trends

Kauai Left Powerless As Hurricane Lowell Skirts Islands

Hurricane Lowell passed west of Hawaii but crippled Kauai with near-total power loss and severe flooding, demonstrating the storm's wide, destructive reach.

Sep 9, 20264 min
A cinematic shot inside a high-tech financial data center, with abstract light visualizations representing volatile currency markets.Fintech

Poland's Final Inflation Bet Pays Off or Blows Up Soon

A massive bet on Polish rate hikes is clashing with central bank inaction, creating a volatile mispricing that could force a violent correction in the EUR/PLN p

Sep 9, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.