The dangerous part here is the exposed people data. Payroll, bank details, IDs, medical records, and HR files can be reused for identity theft, fake payment changes, and highly tailored social engineering long after the breach itself is contained.
ShinyHunters claims it has 297 GB of data and 429,000 files from the Council of Europe, spread across HR, Secretariat, the Parliamentary Assembly, and other departments. The claimed haul includes payroll records for more than 10,000 employees from 2011 to 2026, more than 14,000 CVs, bank account information, tax and social security data, and medical records, with a June 16 deadline before public release.
The forward risk is persistent. Once this kind of personnel data is out, former staff, partners, and vendors can be targeted for years through phishing, account takeover attempts, and fraudulent payment requests.