CSIDB logo
Incident

Autoriteit Persoonsgegevens

Incident posture

Attack window
Feb 2026
Location
Netherlands
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 09:26

Linked entities

Victim
Autoriteit Persoonsgegevens
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) was compromised alongside the European Commission and the Judicial Council through exploitation of zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile, leading to unauthorized access to work‑related information including names, email addresses, and phone numbers. The breach was detected and contained within nine hours for the European Commission, while the Dutch authority confirmed the data exposure as part of the same incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In February 2026, the European Commission, the Dutch Data Protection Authority (known as the Autoriteit Persoonsgegevens), and the Dutch Judicial Council disclosed that they had been compromised through exploitation of critical zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile. The attackers gained access to work‑related data, specifically names, email addresses, and phone numbers, affecting the Dutch incident involving the Autoriteit Persoonsgegevens and the Judicial Council. The European Commission reported that it detected the intrusion and contained the breach within nine hours of discovery, limiting further exposure. No public attribution of the threat actor was provided in the disclosure, and the statement did not indicate whether any data was exfiltrated beyond the accessed fields. The incident was noted alongside other February 2026 events in the timeline of significant cyber incidents, highlighting the use of zero‑day flaws in mobile management software as a recurring attack vector.

The Dutch authorities did not release details on the number of records compromised or the specific systems involved beyond the Ivanti platform. The timeline entry does not describe any service disruption, financial loss, or regulatory penalties resulting from the breach. The European Commission’s rapid containment was cited as a factor that prevented the incident from escalating further. No follow‑up actions such as patch deployment, forensic analysis, or notification to affected individuals were detailed in the source material. The account ends with the confirmation that the breach was identified and reported publicly in February 2026.

Sources

Sources available to members: 1 source.

CSIDB