ShinyHunters claimed it breached the Council of Europe and stole roughly 297 GB of data, saying it exfiltrated more than 429,000 files from multiple departments and threatening to publish the material unless the organization makes contact by June 16. The gang’s leak-site post described a haul spanning the Secretariat, human resources, payroll administration, parliamentary and conference-related units, and said the cache includes payslips, personnel files, CVs, payroll exports, contract records, and performance evaluations affecting more than 10,000 staff.
The allegedly stolen records contain highly sensitive personal data, including names, addresses, dates of birth, salaries, bank details, tax and social security information, and medical or absence records. The Council of Europe said it is investigating the claims and had not confirmed a breach at the time of reporting, while the incident was linked in coverage to ShinyHunters’ broader run of extortion and data-theft operations involving Salesforce-related intrusions, Snowflake customer breaches, and reported exploitation of an Oracle PeopleSoft zero-day.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After the alleged ransom deadline passed, ShinyHunters reportedly published a 4.7 GB compressed dataset tied to its claimed Council of Europe breach. The leaked archive was said to contain more than 429,000 files spanning multiple divisions and years, including sensitive personnel, financial, and medical information.
Xakep reported that ShinyHunters said the alleged Council of Europe breach was carried out via Oracle PeopleSoft zero-day CVE-2026-35273. The report also said Google Threat Intelligence Group and Mandiant observed exploitation of the flaw from at least 2026-05-27 through 2026-06-09.
The Council of Europe told BleepingComputer it was investigating and assessing ShinyHunters' claims but had not confirmed that a breach occurred. SecurityWeek likewise reported that the organization had not publicly acknowledged the incident at the time of reporting.
ShinyHunters posted that it had stolen roughly 297 GB of Council of Europe data, including more than 429,000 files from HR, payroll, and other departments, and threatened to publish the data unless contacted by June 16, 2026. The claimed haul allegedly affects over 10,000 staff and includes sensitive personal, financial, and medical information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetechrepublic.com
Open sourcexakep.ru
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcehookphish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.