ShinyHunters extortion group claims Council of Europe data breach
ShinyHunters extortion group has claimed theft of over 429,000 documents โ including more than 409,000 payslips covering 10,000+ Council of Europe staff โ and, after the Council reportedly refused to pay, made portions of the data permanent on their dark web leak site. The Council of Europe has confirmed it is investigating. Trade reporting links the intrusion to an Oracle PeopleSoft PeopleTools vulnerability (CVE-2026-35273) that ShinyHunters has exploited across 100+ organizations. No insured loss or claims activity has been reported; the Council's cyber insurance posture remains unknown.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Loss pathway centres on alleged exfiltration of highly sensitive payroll, HR, financial, and medical PII from a 46-state intergovernmental organisation, attributed to a threat actor with a documented pattern of third-party SaaS and zero-day exploitation. Evidence currently rests on the threat actor's own dark-web postings and trade/mainstream-media reporting; the Council has only confirmed an investigation is under way. No confirmed insured loss and no London Market claims activity have been reported, and the Council's cyber insurance posture is unconfirmed. Materiality is driven primarily by systemic accumulation risk for cyber insurers monitoring ShinyHunters' multi-victim SaaS and ERP exploitation campaigns rather than by a confirmed single-victim loss.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialAffected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts