ShinyHunters published 297 gigabytes of Council of Europe employee data after the intergovernmental body failed to meet its June 16 ransom deadline — and the criminal group then announced that every file it has ever stolen will now be made permanently available through a new network of mirrors and torrent downloads, removing any possibility of forced takedown. The Council of Europe, which oversees the European Convention on Human Rights across 46 nations, confirmed Friday it is investigating the incident but has offered no notification plan for the more than 10,000 current and former employees, contractors, and job applicants whose bank account details, medical records, salary histories, and social security data are now irrevocably online.
The breach was enabled by a critical zero-day vulnerability in Oracle PeopleSoft — the same enterprise HR software platform used by universities, hospitals, and government agencies worldwide — that Mandiant, Google’s threat intelligence unit, confirmed was actively exploited across more than 100 organizations before Oracle issued a single word of warning.
Council of Europe Breach Scope: What Was Taken
The exfiltrated dataset covers 15 years of institutional records. ShinyHunters claims the archive includes more than 409,000 payslips for over 10,000 staff spanning 2011 through 2026, along with more than 14,000 CVs, over 3,700 in-house personnel files, and thousands of additional documents drawn from multiple Council departments — including the Secretariat, the Human Resources Directorate, the Parliamentary Assembly, and the European Directorate for the Quality of Medicines and Healthcare.
The personal data exposed in the leak is extensive: names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, tax and social security information, and medical records. Internal operational records in the cache include mission travel overpayments, interpreter scheduling and 2026 salary scales, Blue List rosters, absence and illness reports, URSSAF payroll data, performance evaluations, and payroll exports.
The combination of financial, medical, and identity records in a single archive creates conditions for long-term, high-precision fraud. As Cybernews researchers noted, the scope of the breach allows the construction of an extremely detailed victim profile — with enough specificity to enable targeted phishing, identity theft, financial fraud, and blackmail. Because the data includes records from the Council’s human rights casework apparatus, internal files also carry institutional sensitivity beyond individual employee risk.
How CVE-2026-35273 Gave ShinyHunters Passwordless Access to HR Systems
The vulnerability at the center of this campaign — CVE-2026-35273 — sits in PeopleSoft’s Environment Management Hub component, known internally as PSEMHUB. Oracle rates it 9.8 out of 10 on the Common Vulnerability Scoring System scale. The flaw’s defining characteristic is that it requires no authentication: an attacker with nothing more than network access to an exposed PSEMHUB endpoint over standard HTTP can execute arbitrary code on the server.
ShinyHunters describes the attack as a “gadget chain” — a technique that links CVE-2026-35273 with older, previously known vulnerabilities to achieve server takeover that neither flaw enables independently. Mandiant and Google’s Threat Intelligence Group observed that once inside, the attackers deployed customized MeshCentral agents disguised as legitimate cloud endpoints, which they used to run administrative command queries and push a custom lateral movement script across each compromised environment. Exfiltration was compressed using zstd, a high-speed compression format, and pushed outward before defenders could detect the pattern.
Critically, the attackers operated entirely within PeopleSoft’s own application logic. To the application layer, the access appeared indistinguishable from that of a legitimate authorized user — a design-level constraint that made conventional anomaly detection ineffective during the attack window.
That window ran from May 27 through June 9 — two weeks during which Oracle had published no advisory and no mitigation existed. SecurityWeek confirmed that CISA added CVE-2026-35273 to its Known Exploited Vulnerabilities catalog on June 12, ordering federal agencies to apply Oracle’s mitigations by June 15. No full patch has been confirmed as of publication; organizations running PeopleSoft PeopleTools versions 8.61 or 8.62 with the Environment Management Hub accessible from outside their network perimeter remain at risk.
The Pay-or-Leak Playbook and Why the Council Did Not Pay
ShinyHunters operates on a model designed to generate maximum pressure without deploying ransomware encryption. Rather than locking systems, the group posts a target to its Tor-hosted leak site alongside a sample of allegedly stolen data, sets a short ransom deadline, and publishes everything if the victim fails to initiate contact. The model eliminates the operational overhead of ransomware while concentrating leverage in the threat of permanent public disclosure.
The Council of Europe was posted to the group’s dark-web portal on June 14-15 with a June 16 deadline. “This is a final warning to reach out by 16 June 2026 before we leak along with several annoying (digital) problems that’ll come your way,” the group wrote on its leak site, according to BleepingComputer. The Council issued a single public statement — that it was investigating and had no further comment — and did not meet the deadline.
The data was subsequently published.
The FBI has consistently advised organizations against paying extortion demands, citing evidence that payment does not guarantee data deletion and directly funds further criminal operations. Instructure, the Canvas platform developer, chose a different path in May 2026: it paid the group’s ransom demand and received what it characterized as a “shred log” confirming data deletion. Security researchers widely criticized the decision, noting that whether ShinyHunters actually destroyed the data — or had already distributed copies across multiple infrastructure nodes — remains unverifiable.
ShinyHunters Upgrades to Permanent Infrastructure: Mirrors and Torrents
On June 18, ShinyHunters announced a significant infrastructure expansion that changes the risk calculus for every current and future victim. The group deployed multiple data mirrors and announced plans to distribute all stolen files through torrent networks, promising that the data would remain online “until the end of time.”
“To improve your downloading experience, we are currently deploying multiple data mirrors to ensure faster, more reliable download speeds,” the group stated, with plans to eventually provide torrent links for all files in its possession. The distribution system now incorporates a Proof of Work queue mechanism before a downloader can access files — a design that adds friction against automated scraping while simultaneously making the infrastructure more resilient against takedown efforts.
This development eliminates forced hosting takedowns as a viable response strategy for any institution whose data has already been published. Where past victims could at least seek court orders targeting specific servers, a torrent-distributed dataset propagates across thousands of independent nodes simultaneously and cannot be meaningfully removed from public circulation. For the Council of Europe employees whose records were published, this converts what might otherwise have been a recoverable breach into a permanent identity theft risk. It also retroactively worsens the exposure for every organization ShinyHunters has previously targeted.
A Cybercrime Brand That Has Survived Every Law Enforcement Action
The Council of Europe breach is one node in a campaign that Cato Networks research published Friday describes as a structural evolution rather than a criminal spree. The firm characterizes ShinyHunters as having transformed from a database-driven hacking crew into a “cybercrime brand” capable of surviving arrests, infrastructure seizures, and operator turnover — reemerging within days or weeks after each law enforcement action.
The group has operated since 2019 and weathered multiple serious disruptions. In 2022, French national Sébastien Raoult was arrested; he was sentenced to three years in prison and ordered to pay $5 million in restitution in January 2024. Four additional suspected members were arrested in France in June 2025. Neither action interrupted operations. As Cato Networks researchers noted, the group’s decentralized structure makes it resilient to individual arrests in the same way that pulling weeds leaves roots intact.
In 2026 alone, the group has claimed responsibility for breaching more than 40 organizations. Its PeopleSoft campaign exploited CVE-2026-35273 across more than 100 organizations — 68 percent of which were universities or colleges — before the vulnerability was publicly disclosed. The University of Nottingham, an earlier confirmed victim in the same campaign, saw personal and academic records for approximately 454,600 current and former students published after it refused to pay. In separate campaigns exploiting Salesforce misconfiguration and stolen OAuth tokens, the group claims to have stolen more than 1.5 billion records from 760 companies. The FBI issued a formal advisory in May 2026 urging victims not to pay ransom demands.
The group is affiliated with The Com, a loose international cybercrime network that also includes elements of Scattered Spider and former Lapsus$ members. Google’s threat intelligence organization monitors ShinyHunters activity across several distinct clusters — identified as UNC6040, UNC6240, and UNC6661 — each tracking different campaigns and attack methodologies under the shared brand.
What Council of Europe Employees and Contractors Should Do Now
Security professionals recommend that anyone who worked for or with the Council of Europe and may appear in records spanning 2011 through 2026 take the following steps immediately.
Place fraud alerts with major credit bureaus and financial institutions. With bank account numbers, social security data, and salary histories now publicly available in a permanent archive, the risk of account takeover, fraudulent loans, and tax fraud is immediate and ongoing.
Monitor for phishing attempts that reference specific personal details. The level of specificity in the exfiltrated data — combining home addresses, phone numbers, employment history, medical records, and salary information — enables highly personalized social engineering attacks. Any communication that references specific details about salary, employment dates, or medical history should be treated as a red flag regardless of how credible the sender appears.
Review financial accounts and credit reports for unauthorized activity. Because the breach includes bank account details and URSSAF payroll data, direct financial fraud is possible without the victim having provided any additional information to an attacker.
The Council of Europe has not announced a formal notification process or credit monitoring assistance for affected individuals as of publication.
Frequently Asked Questions
Was my data exposed in the Council of Europe breach?
If you are a current or former employee, contractor, or job applicant at the Council of Europe whose records date from 2011 through 2026, your information is likely included in the exfiltrated dataset based on ShinyHunters’ published claims. The Council of Europe has not confirmed a formal notification process, and the organization has offered no public guidance on checking individual exposure. You can monitor breach notification services such as Have I Been Pwned, but the most direct protective step is to treat your financial and identity data as compromised immediately — place fraud alerts, monitor accounts, and stay alert for highly personalized phishing attempts that reference details only a payroll or HR system would contain.
How did ShinyHunters get into the Council of Europe’s systems?
The group exploited CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft’s Environment Management Hub. Rated 9.8 out of 10 in severity, the flaw allowed attackers to execute code on PeopleSoft servers with no authentication required — no password, no phishing, no insider access. ShinyHunters chained this flaw with older known vulnerabilities in a technique they call a “gadget chain,” then used disguised remote-management software to spread access and compress data for exfiltration. Oracle had no advisory published during the two-week exploitation window from May 27 to June 9, meaning every organization compromised in that period had zero defensive recourse.
Is the pay-or-leak model different from ransomware, and does paying actually help?
The pay-or-leak model differs from traditional ransomware in that attackers do not encrypt systems — they only threaten to publish stolen data. This means victims retain full access to their systems throughout the extortion process, but the leverage is the permanent reputational, legal, and personal harm from public data exposure. The FBI advises strongly against paying extortion demands, citing evidence that payment does not guarantee data deletion. Instructure paid ShinyHunters’ ransom in May 2026 and received a claimed confirmation of data deletion, but whether the data was actually destroyed — or had already been distributed across multiple nodes — cannot be independently verified.
What does ShinyHunters’ new torrent infrastructure mean for breach victims?
ShinyHunters announced on June 18 that all data on its leak site will be distributed via mirrors and torrent networks with a stated intention to keep files permanently accessible. For victims of current and past breaches, this eliminates court-ordered hosting takedowns as a viable remedy. Once data enters a torrent distribution network, it propagates across thousands of independent nodes and cannot be meaningfully removed. This applies retroactively to all previously published datasets — not only new ones — permanently worsening the exposure for every organization the group has previously targeted.
