Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-diplomatic-threatbreach-disclosure-notificationmass-credential-exposureendpoint-software-vulnerability

European Institutions Breached via Ivanti Endpoint Manager Mobile Vulnerabilities

Updated 3mo agoFirst seen Feb 9, 202614 sources

The European Commission disclosed it is investigating a breach after detecting traces of an attack against its central mobile device management (MDM) infrastructure used to administer staff mobile devices. The Commission said the incident was contained and the system cleaned within nine hours, and it has not found evidence that managed mobile devices themselves were compromised; however, attackers may have accessed limited staff personal data such as names and mobile phone numbers.

The activity appears consistent with a broader set of intrusions affecting European public-sector bodies tied to vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). Dutch authorities reported that the Dutch Data Protection Authority and the Council for the Judiciary/Justice experienced nearly identical breaches in which unauthorized parties exploited an Ivanti EPMM software flaw to access employee data, including names, email addresses, and phone numbers, suggesting a shared exploitation vector across multiple European institutions’ MDM deployments.

Share:
European Institutions Breached via Ivanti Endpoint Manager Mobile Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Feb 9, 20264mo ago

Dutch government publicly confirms AP and Judiciary breaches

Dutch authorities publicly confirmed that the Dutch Data Protection Authority and the Council for the Judiciary were hacked through Ivanti EPMM vulnerabilities. Officials said unauthorized parties viewed employee contact information while the investigation remained ongoing.

European Commission publicly discloses breach and ongoing investigation

The European Commission publicly confirmed the January 30 incident, saying it is investigating the attack with support from CERT-EU. It stated that only limited staff contact data may have been exposed and that monitoring and hardening efforts are continuing.

Finland's Valtori discloses EPMM-related breach affecting MDM service

Finland's government ICT provider Valtori disclosed a breach tied to exploitation of Ivanti EPMM zero-days in its mobile device management service. The incident potentially affected up to 50,000 users and may have exposed work-related and historical service data.

Jan 30, 20265mo ago

European Commission contains and cleans affected systems within nine hours

Following detection of the January 30 intrusion, the Commission isolated the affected management systems, removed malicious artifacts, and restored operations in roughly nine hours. Investigators said they found no evidence that managed mobile devices themselves were compromised.

European Commission detects intrusion in mobile device management infrastructure

On January 30, the European Commission detected signs of a cyberattack affecting the central infrastructure used to manage staff mobile devices. The intrusion may have exposed limited staff personal data, specifically names and mobile phone numbers.

Jan 29, 20265mo ago

Dutch authorities notify NCSC and take response measures

After the Dutch incidents were identified on January 29, authorities alerted the National Cyber Security Centre, informed affected employees, and began assessing broader impact across central government. The Dutch government also reported the matter to parliament while investigations continued.

Dutch agencies breached via Ivanti EPMM exploitation

On January 29, attackers exploited Ivanti EPMM vulnerabilities to access systems used by the Dutch Data Protection Authority and the Council for the Judiciary. The breach exposed employees' work-related contact data, including names, business email addresses, and phone numbers.

Ivanti discloses and patches two critical EPMM zero-days

Ivanti warned customers in late January about two critical unauthenticated code-injection flaws in Endpoint Manager Mobile, CVE-2026-1281 and CVE-2026-1340, and released fixes and detection guidance. The company said the vulnerabilities had been exploited as zero-days against a limited number of customers.

Jan 28, 20265mo ago

CISA adds Ivanti EPMM flaw CVE-2026-1281 to KEV catalog

CISA added CVE-2026-1281, a critical Ivanti Endpoint Manager Mobile vulnerability, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The move signaled that organizations should urgently remediate exposed EPMM systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Organizations
12 linked
IvantiHackReadShadowServer FoundationWatchTowrSecurity AffairsThe RegisterNational Health ServiceBloombergTinesAPA.azAlgemeen Nederlands PersbureauBarrier Networks
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

European Institutions Breached via Ivanti Endpoint Manager Mobile Vulnerabilities | Mallory