The Council of Europe is investigating data breach claims made by the ShinyHunters extortion group over the weekend. The breach, if confirmed, would affect Europe's oldest intergovernmental body.
The Council of Europe has launched an investigation into allegations that ShinyHunters, a known data extortion group, has breached its systems and obtained sensitive information.
ShinyHunters announced the breach publicly over the weekend, claiming access to Council of Europe data. The group operates by stealing data and threatening to release it unless organizations pay ransoms. This extortion tactic has made them a persistent threat across multiple sectors.
The Council of Europe, established in 1949, is an international organization comprising 46 member states and focused on human rights, democracy, and rule of law across the continent. A successful breach of its systems could potentially expose sensitive information related to member states' operations, legal proceedings, or confidential communications.
The organization has not disclosed specific details about the scope of the alleged breach, the types of data potentially compromised, or the timeline of the incident. Investigations of this scale typically require time to assess the full impact and identify how attackers gained access.
ShinyHunters has previously claimed responsibility for breaches at major companies and organizations. Their pattern involves stealing data, publishing samples as proof, and setting deadlines for payment before releasing the full dataset publicly.
The Council of Europe's investigation will likely involve cybersecurity experts and may trigger notifications to affected member states. Depending on findings, the organization may need to notify individuals whose personal data was compromised under EU data protection regulations.
This incident underscores ongoing cybersecurity challenges faced by high-profile governmental and international organizations, which remain attractive targets for extortion groups seeking both financial gain and publicity.
Cybersecurity professionals are pushing back against apocalyptic hacking predictions from AI industry leaders, calling the warnings technically incoherent and based on fundamental misunderstandings of cybersecurity.
Security expert Bruce Schneier argues that two and a half decades of mass surveillance programs have failed to deliver promised security benefits and should be dismantled. The call comes as surveillance capabilities continue expanding globally.
A security researcher demonstrated a critical vulnerability in Baseten's infrastructure, obtaining full administrative access to the company's production GitHub account in under half an hour. The exploit highlights widespread risks in how companies manage authentication tokens.