The Council of Europe, the 46-member human-rights organisation headquartered in Strasbourg, France, confirmed it is investigating a breach after the extortion group ShinyHunters claimed to have exfiltrated roughly 297GB of internal data. The group said the haul included payroll records covering more than 10,000 employees stretching back to 2011, over 14,000 CVs, contract and purchase-order documents, and personal details including names, national IDs, home addresses, phone numbers and dates of birth.
ShinyHunters also claimed to have taken tax, social security and medical records along with staff performance evaluations and bank account information, and set an extortion deadline giving the Strasbourg headquarters roughly a day to respond before threatening to publish the data. A spokesperson for the Council told reporters only that "we are currently investigating the matter and assessing the situation," declining further comment while the review continues.
The claimed breach adds the Council of Europe to a growing list of ShinyHunters targets in 2026, a group that security researchers have linked to a wave of attacks on Salesforce customers as well as the exploitation of a zero-day vulnerability in Oracle PeopleSoft affecting roughly 100 organisations. For an institution built around protecting personal rights and data across the continent, a breach of its own staff's payroll and medical records lands as a particularly pointed embarrassment.

