Europol confirms incident following alleged auction of staff data

Europol confirms incident following alleged auction of staff data

May 13, 2024 at 07:55AM

Europol is investigating a cybercriminal’s claim of stealing confidential data from its sources. The Europol Platform for Experts is confirmed as the main subject, but no operational data has been compromised. The cybercriminal, operating as IntelBroker, has also targeted Zscaler and the European Parliament’s PEOPLE app. Europol is assessing the situation while the cybercriminal has claimed to have sold the data.

After reviewing the meeting notes, it is evident that Europol is currently investigating a significant cyber incident involving the theft of confidential data from various agency sources. The incident primarily revolves around the Europol Platform for Experts (EPE), which has been offline for maintenance since May 10.

While the agency has not explicitly denied the legitimacy of the cybercriminal’s claims, it has stated that no operational data from Europol has been compromised. However, the cybercriminal, operating under the name IntelBroker, has boasted of accessing classified data, including sensitive discussions and secure messaging features from various divisions of Europol, the European Cybercrime Centre, and other connected projects.

Furthermore, IntelBroker has indicated that the stolen data has been sold and was accepting offers only in Monero, a cryptocurrency. Notably, this incident occurred shortly after the European Parliament announced that data from its PEOPLE recruitment app had been exposed in a separate attack earlier in the year.

There are clear implications for data security and privacy, and this situation warrants increased scrutiny and potential measures to prevent further breaches. The leaked data poses immediate concerns for affected individuals, such as the need to change passwords and remain vigilant against potential scams targeting them.

It’s essential for Europol and other affected organizations to provide transparency and take robust actions to address the existing vulnerabilities and prevent future security breaches. Additionally, there should be a focus on informing and supporting individuals whose data may have been compromised, as well as implementing stronger cybersecurity measures to safeguard sensitive information in the future.

I will continue to monitor the situation and provide any updates as they arise.

Full Article