European Commission discloses breach of mobile device management platform

by

In a press release from the European Commission, the Commission said it detected traces of a cyber-attack on 30 January against the central system that manages staff mobile devices and that the incident may have exposed staff names and mobile numbers.

KEY FACTS

  • Incident Traces of a cyber-attack on the mobile device management platform
  • Date 30 January 2026
  • Data exposed Staff names and mobile telephone numbers may have been accessed
  • Containment System cleaned within nine hours and no device compromise detected

The swift response contained the incident and the system was cleaned within nine hours. No compromise of individual mobile devices was detected.

Work-related contact data such as names, business email addresses and telephone numbers were accessed in breaches linked to vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), according to a Dutch parliamentary document from the Dutch authorities that names the Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr).

The affected product is known as EPMM. Two recent code-injection flaws allow remote attackers to execute arbitrary code on unpatched systems without authentication, increasing the risk to unpatched management infrastructure.

The press release did not disclose how attackers gained access and an investigation remains under way. The incident came days after a January 20 proposal to strengthen cybersecurity rules for critical infrastructure.

WHY IT MATTERS

Breaches of systems that manage large numbers of staff devices can expose widespread contact data even if endpoint compromise is not confirmed. Timely patching and monitoring of enterprise mobility management platforms are essential to limit such exposure.