ShinyHunters Claims 297GB HR and Payroll Data from Council of Europe: Ransomware Claim — What’s Alleged & What To Do
The Council of Europe disclosed a data breach on June 14, 2026, after ShinyHunters claimed to have stolen 297 GB of HR and payroll records containing personal, financial, and medical information of more than 10,000 people. Anyone who may have been affected should check the Council’s notifications and take steps to protect their accounts and personal data.
Breaking down the breach
The reported claim centres on data described as HR records, payroll files, payslips, CVs, employee files, bank details, medical records and salary information. It is said to affect more than 10,000 staff and contractors. The posting appeared on a leak site around 13-14 June 2026 and is presented as separate from other activity attributed to the same group. No independent verification of the data volume, file count or contents has been made public, and the Council of Europe has not issued a statement confirming or denying the claim.
How a breach like this happens
Incidents involving personnel and financial records often begin with an attacker gaining access to an organisation’s internal systems through stolen credentials, unpatched software or misconfigured cloud storage. Once inside, the actor can locate directories that hold payroll exports, scanned documents and database backups. Data of this type is frequently stored in shared folders or legacy HR platforms that receive less frequent security review than customer-facing systems. The material is then compressed and removed before detection systems raise an alert.
Council of Europe and its sector
The Council of Europe is an intergovernmental body whose work covers human rights, legal standards and democratic governance across its member states. Like other international organisations, it maintains records on its own employees and contractors, including recruitment documents, salary administration and, in some cases, health-related information required for employment. A compromise of these records is consequential because the data belongs to individuals working across multiple countries and because the organisation’s role gives its internal processes a degree of public visibility.
The information in question
The claim lists several categories of data: HR records, payroll information, personal details, financial data and medical information. Organisations of this type routinely hold employment contracts, salary histories, bank account numbers for payroll, curriculum vitae and, where relevant, medical certificates or occupational health records. The precise contents of any exfiltrated material remain unconfirmed because the organisation has not published an inventory of affected records.
The real-world impact
Individuals whose salary, bank and medical details are exposed face an elevated risk of identity misuse and targeted fraud. Payroll data can be used to open accounts or file false tax returns, while medical information may be exploited for social-engineering attacks. For the organisation, the incident adds to the administrative burden of investigating the claim, notifying affected staff and reviewing access controls, even if the data’s authenticity is later disputed.
What to do if you're exposed
People who believe their information may be involved should begin by monitoring their bank and credit accounts for unusual activity and placing fraud alerts with major credit bureaus where available. Changing passwords for any work-related accounts and enabling multi-factor authentication reduces the chance of further misuse of credentials. Anyone can run a free exposure scan of their email address against known breach data to check whether their details have appeared in previously published incidents.
- Review bank statements and credit reports regularly.
- Enable multi-factor authentication on email and financial accounts.
- Contact your employer’s HR department for official guidance if you are a current or former staff member.
- Consider a credit freeze if you live in a jurisdiction that offers one.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Lithuania State Registers Leak Impacts 540K CitizensLa Pampa Leaks Exposes 5.8M Uruguayan Citizen RecordsUnion County, Ohio Paid $1M to Kairos in Data ExtortionAflac Japan Discloses Breach Impacting 4.38M CustomersLatest breaches
Publicly posted by shinyhunters — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.