1. [News](/news)
2. Council of Europe data breach: ShinyHunters claims theft of HR and payroll records

The Council of Europe

# Council of Europe data breach: ShinyHunters claims theft of HR and payroll records

A data breach involving Council of Europe was reported in June 2026. See incident details, impact on staff, and recommended security measures.

UpGuard Team June 15, 2026

Table of Contents

* [What happened in the Council of Europe data breach?](#what-happened-in-the-council-of-europe-data-breach)
* [Who is behind the incident?](#who-is-behind-the-incident)
* [Impact and risks for Council of Europe staff](#impact-and-risks-for-council-of-europe-staff)
* [How to protect against similar security incidents](#how-to-protect-against-similar-security-incidents)

## Key facts: Council of Europe data breach

* Date reported

  June 15, 2026

* Target entity

  Council of Europe

* Source of breach

  Extortion group ShinyHunters

* Data types

  Names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, medical records, payslips, CVs

* Status

  Under investigation; reported on June 15, 2026.

* Severity

  High; exposure of sensitive HR, financial, and medical data poses significant identity theft and fraud risks.

## What happened in the Council of Europe data breach?

The Council of Europe (coe.int) is currently investigating a significant security incident following claims by the extortion group ShinyHunters. The breach, first reported on June 15, 2026, allegedly involves the theft of over 429,000 documents containing sensitive human resources and payroll information. According to the threat actors, the stolen data includes more than 409,000 payslips for over 10,000 staff members, spanning a period from 2011 to 2026.

The incident is classified as high severity due to the depth of personal and financial information involved. Exposed records reportedly contain names, home addresses, salaries, bank account details, and even medical records. ShinyHunters has threatened to leak the files publicly on June 16, 2026, if their demands are not met. While the investigation is ongoing, such breaches typically lead to targeted phishing, financial fraud, and long-term identity theft risks for the affected individuals.

## Who is behind the incident?

ShinyHunters is a well-known extortion group that has been active since at least 2020. The group is notorious for targeting high-profile organizations and stealing large databases, which they then use to demand ransoms or sell on underground forums. Unlike traditional ransomware groups that encrypt systems, ShinyHunters primarily focuses on data exfiltration and extortion. They have previously claimed responsibility for breaches involving major tech companies and retailers. Their methods often involve exploiting vulnerabilities in cloud environments or using stolen credentials to gain unauthorized access to internal repositories and document management systems.

## Impact and risks for Council of Europe staff

The impact on current and former staff of the Council of Europe is substantial. With the exposure of payslips, bank details, and medical information, affected individuals face a high risk of identity theft and financial fraud. Malicious actors could use the stolen data to open fraudulent accounts or conduct unauthorized transactions. Furthermore, the inclusion of home addresses and medical records introduces significant privacy concerns and the potential for targeted harassment.

Staff members should remain vigilant against sophisticated phishing attempts that may use their personal details to appear legitimate. It is essential to monitor bank statements and credit reports for any suspicious activity. Implementing multi-factor authentication on all personal and professional accounts and utilizing identity theft protection services are critical steps for those affected. Prompt transparency from the organization helps in mitigating these long-term risks.

## How to protect against similar security incidents

Given the exposure of sensitive HR and financial data at the Council of Europe, staff members and stakeholders should take immediate steps to secure their personal information and monitor for signs of fraud.

* **Enroll in identity theft and credit monitoring.** Sign up for a credit monitoring service to receive alerts about new accounts opened in your name. Place a fraud alert or credit freeze on your files with major credit bureaus to prevent unauthorized credit applications.
* **Secure financial accounts and monitor transactions.** Notify your bank and financial institutions about the potential compromise of your bank account details. Review bank statements regularly for unauthorized charges and enable transaction notifications for all financial activity.
* **Implement phishing-resistant multi-factor authentication.** Enable MFA on all personal email and financial accounts, preferably using hardware keys or authenticator apps. Be wary of unsolicited communications requesting further personal information or login credentials, as attackers may use stolen data to build trust.
* **Enhance organizational attack surface management.** Organizations should deploy continuous monitoring tools to identify exposed assets and data leaks in real-time. Regularly audit access permissions to sensitive HR and payroll systems to ensure the principle of least privilege is strictly maintained.

> Taking proactive measures now can significantly reduce the long-term impact of this data exposure.

## Frequently asked questions

### What happened in the Council of Europe security breach?

ShinyHunters claimed responsibility for a security attack on Council of Europe (coe.int) in June 2026. The incident was first reported on June 15, 2026.

### When did the Council of Europe breach occur?

The Council of Europe breach was publicly reported on June 15, 2026. ShinyHunters referenced the incident around that time, but the attack may have occurred earlier.

### What data was exposed?

The types of data involved in the Council of Europe incident include names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, and medical records. ShinyHunters has claimed to possess over 409,000 payslips.

### Is my personal information at risk?

If you interacted with Council of Europe, there’s a possibility your personal information could be affected. Because this incident targets internal HR records, affected staff face direct risks of targeted phishing, financial fraud, and potential blackmail.

### What steps should companies take after being breached?

The Council of Europe is expected to secure systems, notify affected parties, provide guidance on protective actions, review security measures, and deploy attack surface management to prevent future occurrences.

## Is your organization exposed to a similar risk?

UpGuard continuously monitors vendors for exposed credentials and infrastructure risk, so you can catch the next breach before it becomes a headline.

[Start your free trial](https://cyber-risk.upguard.com/register/trial)

## How secure is The Council of Europe?

The Council of Europe is an international organization dedicated to upholding human rights, democracy, and the rule of law across Europe that utilizes coe.int as its official online platform to provide information regarding its conventions, legal standards, and monitoring activities to its member states and the public.

* View our free preliminary report on The Council of Europe's security posture
* 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

[View The Council of Europe's score View score](/security-report/the-council-of-europe)

[https://coe.int/](/security-report/the-council-of-europe)

## Latest news

Stay up-to-date with the latest news in cybersecurity.

* ### [Hugging Face data breach: key facts and what we know so far](/news/hugging-face-data-breach-2026-07-20)

  A data breach involving Hugging Face was reported in July 2026. See incident details, impact on customers, and recommended security measures.

  UpGuard Team July 20, 2026

* ### [EY data breach: what happened and what's at risk](/news/ey-data-breach-2026-07-19)

  A data breach involving EY was reported in July 2026. See incident details, impact on customers, and recommended security measures.

  UpGuard Team July 17, 2026

* ### [South Florida Injury & Convenient Care data breach exposes names and Social Security numbers](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

  A data breach involving South Florida Injury & Convenient Care was reported in July 2026. See incident details, impact on customers, and security measures.

  UpGuard Team July 16, 2026

* ### [Park West Psychology data breach: what happened and what's at risk](/news/park-west-psychology-data-breach-2026-07-16)

  A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.

  UpGuard Team July 16, 2026

* ### [Fall River Municipal Credit Union data breach: what happened and what's at risk](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

  A data breach involving Fall River Municipal Credit Union was reported in July 2026. See incident details, impact on customers, and recommended security measures.

  UpGuard Team July 16, 2026

* ### [NPCIL data breach: World Leaks claims exposure of Kudankulam Nuclear Power Plant files](/news/npcil-data-breach-2026-07-16)

  A data breach involving NPCIL was reported in July 2026. See incident details, impact on customers, and recommended security measures.

  UpGuard Team July 16, 2026

[View all news](/news)

## Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.
