NATO investigated claims by hacktivist group SiegedSec that it had breached an alliance platform used to share unclassified information. Reports said the group posted screenshots and alleged stolen files online, asserting it had accessed a NATO Community of Interest portal rather than classified military networks. NATO acknowledged it was examining the incident and said the affected environment handled unclassified data.
Coverage indicated the alliance was working to verify the scope and authenticity of the exposed material while emphasizing that there was no indication classified systems were compromised. Subsequent reporting said the inquiry remained active as officials assessed what information may have been accessed or leaked and whether the intrusion involved a limited web-facing collaboration service rather than NATO’s core operational infrastructure.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
SiegedSec claimed it had compromised six NATO web portals, stolen more than 3,000 files totaling about 9GB, and published links to the alleged data on Telegram. NATO said it was actively addressing multiple IT security incidents affecting some unclassified websites, added cybersecurity measures, and reported no impact on missions, operations, or deployments.
By early October, NATO said it had found no evidence that its systems were compromised in connection with the alleged SiegedSec attack. The alliance indicated the matter had been investigated and the earlier claims were not substantiated as a breach of NATO systems.
NATO said it was investigating the apparent intrusion claim involving an unclassified information-sharing platform after SiegedSec posted alleged stolen data online. The alliance stated there was no impact on classified missions, operations, or networks based on initial findings.
Hacktivist group SiegedSec publicly claimed it had compromised a NATO unclassified information-sharing portal and stolen data. Reports indicated the allegedly accessed system was used for sharing unclassified information rather than classified NATO networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
scmagazine.com
Open sourcetheregister.com
Open sourcetheregister.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.