Menu
Browse

Cyber Incident Victim: Autoriteit Persoonsgegevens

Date

Feb 2026

Location

Netherlands

Status

Unknown

Updated

2026-07-18 03:49

Timeline
Occurred
Feb 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) together with the Judicial Council and the European Commission confirmed they were compromised through zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile. The breach exposed work‑related data including names, email addresses and phone numbers, while the European Commission reported that it contained its breach within nine hours. No further details about the attackers or the exact volume of data were disclosed in the public report.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In February 2026 the Dutch Data Protection Authority, known as the Autoriteit Persoonsgegevens, confirmed that it had been subjected to a cyberattack. The authority disclosed that the breach occurred through the exploitation of critical zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile. The disclosure was made jointly with the European Commission and the Dutch Judicial Council, which reported similar compromises. The exact date of the discovery within February 2026 was not specified in the source material.

Cyber Incident Image

The compromised data consisted of work‑related information, specifically names, email addresses, and telephone numbers stored within the authority’s systems. No other categories of personal data, such as financial identifiers or health information, were mentioned as being accessed in this incident. The breach was described as part of a broader campaign that leveraged the same Ivanti zero‑day flaws to target multiple European entities.

While the European Commission stated that it had contained its breach within nine hours of detection, the source does not provide comparable containment details for the Dutch Data Protection Authority. The authority’s public confirmation acknowledged the exploitation of the Ivanti vulnerability and the resulting access to staff contact information. No further details regarding mitigation steps, notification procedures, or remediation timelines were included in the reported account.

Sources
Sources available to members
1 source