CSIDB logo
Incident

Valtori

Incident posture

Attack window
Jan 2026
Location
Finland
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 09:36

Linked entities

Victim
Valtori
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

Valtori, the public managed services provider for Finland's government, suffered a breach after attackers exploited a critical vulnerability in Ivanti's Endpoint Manager Mobile product, gaining access to names, email addresses, phone numbers and device details of roughly fifty thousand individuals linked to the central government. The same vulnerability was used in attacks against the European Commission's mobile device management infrastructure and against two Dutch government agencies, the Data Protection Authority and the Council for the Judiciary, which also disclosed compromises around the same time. Valtori disclosed the incident publicly, noting the breach originated from a commercial mobile device management service that had been patched days earlier.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 29, 2026, Ivanti disclosed two critical vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, identified as CVE-2026-1281 and CVE-2026-1340, both enabling remote code execution and receiving a CVSS score of 9.8. Ivanti released a temporary patch to address the flaws and acknowledged that a very limited number of customers had already been exploited at the time of disclosure. The following day, January 30, cyberattacks leveraging these EPMM vulnerabilities were observed against the European Commission’s central infrastructure that manages mobile devices. The attack on the European Commission lasted approximately nine hours and resulted in the compromise of staff names and mobile numbers, although no direct compromise of mobile devices was detected. On the same day, Valtori, the public managed services provider for the Finnish government, experienced an attack of identical nature. The Valtori breach affected roughly 50,000 individuals linked to the central government, exposing names, email addresses, phone numbers, and other device‑related details. Both incidents were subsequently disclosed publicly on February 5, 2026. Neither Valtori nor the European Commission initially named EPMM as the cause of the breaches. Valtori did indicate that the intrusion occurred via a vulnerability in a “commercial mobile device management service,” which matched the Jan 29 disclosure. Independent verification by Dark Reading confirmed that the European Commission’s compromise was indeed through EPMM.

On February 6, two Dutch government entities—the Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr)—acknowledged that they had also been breached. Unlike the earlier disclosures, these Dutch agencies explicitly identified Ivanti EPMM as the vector of their attacks. The disclosed impacts across all affected organizations included the loss of personal data such as names, contact information, and device details, but no evidence of persistent mobile device control was reported. In its public statement, Valtori noted that the breach stemmed from the previously disclosed EPMM vulnerability and emphasized that the incident was limited to data exfiltration. The European Commission’s statement similarly described the incident as a nine‑hour intrusion that yielded staff identifiers but did not result in device takeover. Both organizations indicated that they had initiated internal investigations and were working with relevant national cybersecurity authorities to assess the scope of the data loss. No public details were provided regarding any specific containment steps taken beyond the initiation of investigations.

Shadowserver recorded a second, more voluminous wave of attempted exploitation against Ivanti EPMM that peaked around February 9. Analysis by Greynoise showed that none of the indicators of compromise (IoCs) published by Ivanti corresponded to this surge in activity. Approximately 83 % of the observed attempts were traced to a single IP address hosted on a bulletproof hosting service. As of the article’s publication date on February 12, 2026, that IP address remained active in general traffic. Ivanti responded by urging customers to apply the temporary patch released on January 29 and to review their appliances for signs of pre‑patch exploitation. The company also supplied high‑fidelity IoCs, technical analysis details, and an exploitation detection script developed in cooperation with the NCSC NL. Ivanti stated that applying the patch was the most effective measure to prevent further exploitation, regardless of evolving IoCs. No additional public disclosures regarding further compromises or remediation timelines were included in the reported sources.

Sources

Sources available to members: 1 source.

CSIDB