CSIDB logo
Incident

Judicial Council

Incident posture

Attack window
Feb 2026
Location
Netherlands
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 09:00

Linked entities

Victim
Judicial Council
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

The Judicial Council was hacked together with the European Commission and the Dutch Data Protection Authority through zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile. Attackers accessed work‑related data including names, email addresses and phone numbers, while the Commission said it contained its breach within nine hours.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In February 2026, the Judicial Council confirmed that it had been hacked alongside the European Commission and the Dutch Data Protection Authority. The attackers exploited critical zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile to gain access. This disclosure was part of a broader timeline of significant cyber incidents recorded for that month.

The breach resulted in the exposure of work‑related data, specifically names, email addresses, and phone numbers, in the Dutch incident that involved both the Judicial Council and the Dutch Data Protection Authority. The European Commission stated that it managed to contain its breach within nine hours of detection. No further details about the exact volume of records compromised were provided in the source material.

The Judicial Council confirmed the breach, which constituted its public acknowledgment of the incident. No additional information regarding containment timelines, mitigation steps, or post‑incident activities for the Judicial Council was included in the source material. The incident highlights the use of Ivanti Endpoint Manager Mobile zero‑day exploits as a vector for simultaneous intrusions across multiple European entities. The source does not indicate whether any ransom demand was associated with the Judicial Council breach.

Sources

Sources available to members: 1 source.

CSIDB