INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

European Commission Discloses Staff Data Breach Exposing Personal Information

| 2026-02-09 09:49 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A data breach was discovered at the European Commission on January 30, where attackers exploited vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) software to access employee names and business email addresses of nearly 50 employees from two Dutch authorities. The attack is believed to be linked to similar attacks targeting other institutions that exploit these same vulnerabilities. Ivanti had warned of the critical vulnerabilities CVE-2026-1281 and CVE-2026-1340 on January 29, which were exploited in zero-day attacks. The breach was contained within nine hours by the Commission's swift response, with no compromise of mobile devices detected.
Technical Mitigations AI-generated
• Patch Ivanti Endpoint Manager Mobile (EPMM) to address CVE-2026-1281 and CVE-2026-1340 vulnerabilities. • Monitor for code-injection attacks targeting EPMM servers using techniques such as network traffic analysis or endpoint monitoring tools. • Block or hunt for suspicious activity related to the exploitation of Ivanti EPMM vulnerabilities, including indicators such as unusual login attempts or unauthorized access to employee data.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-1340CVE-2026-1340 CVE-2026-1281CVE-2026-1281
Target & Sectors
Global Scope
Incident Timeline
‎2026/02/09
Threat actors exploited vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) software to access employee names, business email addresses, and telephone numbers.
infrastructure Ivanti
infrastructure 50 Ivanti EPMM servers
Tactical Metrics
Metrics
infrastructure
​Ivanti
Affected Product
Metrics
infrastructure
50
Ivanti Epmm Servers
Intelligence Sources
BleepingComputer 2026-02-09