Cyber Incident Victim: Autoriteit Persoonsgegevens
Timeline
Summary
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) together with the Judicial Council and the European Commission confirmed they were compromised through zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile. The breach exposed work‑related data including names, email addresses and phone numbers, while the European Commission reported that it contained its breach within nine hours. No further details about the attackers or the exact volume of data were disclosed in the public report.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In February 2026 the Dutch Data Protection Authority, known as the Autoriteit Persoonsgegevens, confirmed that it had been subjected to a cyberattack. The authority disclosed that the breach occurred through the exploitation of critical zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile. The disclosure was made jointly with the European Commission and the Dutch Judicial Council, which reported similar compromises. The exact date of the discovery within February 2026 was not specified in the source material.

The compromised data consisted of work‑related information, specifically names, email addresses, and telephone numbers stored within the authority’s systems. No other categories of personal data, such as financial identifiers or health information, were mentioned as being accessed in this incident. The breach was described as part of a broader campaign that leveraged the same Ivanti zero‑day flaws to target multiple European entities.
While the European Commission stated that it had contained its breach within nine hours of detection, the source does not provide comparable containment details for the Dutch Data Protection Authority. The authority’s public confirmation acknowledged the exploitation of the Ivanti vulnerability and the resulting access to staff contact information. No further details regarding mitigation steps, notification procedures, or remediation timelines were included in the reported account.
