Dutch agencies hit by Ivanti EPMM exploit exposing employee contact data
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读全文,抓住主要信息。 文章主要讲的是荷兰的一些机构被黑客攻击了,利用了Ivanti EPMM的漏洞,导致员工的联系方式被泄露。具体来说,荷兰的数据保护局和司法委员会受到了影响。攻击者获取了员工的姓名、工作邮箱和电话号码。荷兰的国家网络安全中心在1月29日被通知到这个问题,并采取了措施,比如通知受影响的员工,并监控事件的影响。 此外,欧盟委员会也报告了类似的安全事件,他们的移动设备管理平台被入侵,可能泄露了部分员工的数据。不过他们迅速控制住了情况,并没有设备被破坏。 总结下来,关键点包括:荷兰机构、Ivanti EPMM漏洞、员工数据泄露、荷兰和欧盟的应对措施。我需要把这些信息浓缩到100字以内,同时保持语句通顺。 可能会这样组织:荷兰数据保护局和司法委员会因Ivanti EPMM漏洞遭攻击,员工联系信息泄露。荷兰国家网络安全中心已介入调查,并采取措施应对潜在影响。欧盟委员会也报告了类似事件。 检查一下字数是否在限制内,并确保没有遗漏重要信息。 </think> 荷兰数据保护局和司法委员会因Ivanti EPMM漏洞遭攻击,员工联系信息泄露。荷兰国家网络安全中心已介入调查,并采取措施应对潜在影响。欧盟委员会也报告了类似事件。 2026-2-10 10:11:48 Author: securityaffairs.com(查看原文) 阅读量:0 收藏

Dutch agencies hit by Ivanti EPMM exploit exposing employee contact data

Pierluigi Paganini February 10, 2026

Dutch agencies confirmed attacks exploiting Ivanti EPMM flaws that exposed employee contact data at the data protection authority and courts.

Dutch authorities said cyberattacks hit the Dutch Data Protection Authority and the Council for the Judiciary after hackers exploited newly disclosed flaws in Ivanti Endpoint Manager Mobile (EPMM). The incidents were reported to parliament, and the National Cyber Security Center was alerted on January 29 after the vendor disclosed the vulnerabilities. EPMM manages mobile devices, apps, and security, and the attacks exposed employee contact information.

“State Secretary Rutte (JenV) and State Secretary Van Marum (BZK) informed the House of Representatives about the exploitation of a vulnerability in Ivanti Endpoint Manager Mobile (EPMM) at the Dutch Data Protection Authority (AP) and the Judicial Council (Rvdr). EPMM is a system for managing mobile devices, apps, and content, including their security.” reads the advisory. “On 29 January the National Cyber Security Centre (NCSC) was informed by the supplier of vulnerabilities in EPMM. EPMM is used to manage mobile devices, apps and content, including their security. Based on the information known at this moment, I can report that at least the AP and the Rvdr have been affected. “

Attackers accessed work-related contact details of AP staff, including names, work emails, and phone numbers. Authorities quickly took action, informed affected employees, and reported the incident. The NCSC continues to monitor the issue and assess any wider impact across government systems.

“It is now known that work‑related data of AP employees, such as name, business e‑mail address and telephone number, have been accessed by unauthorised parties.” continues the advisory. “As soon as the incident was discovered, measures were taken immediately. In addition, the employees of the AP and the Rvdr were informed.”

This week, the European Commission announced it is investigating a cyberattack on its mobile device management platform after detecting intrusion traces. Attackers may have accessed some staff data, including names and phone numbers, but so far they have not compromised any devices.

On 30 January, the European Commission detected a cyberattack on its mobile device management system. The organization pointed out that no mobile devices were compromised. The Commission contained and cleaned the system within nine hours. It continues to monitor security, strengthen cybersecurity, and review the incident to improve protections, reflecting its commitment to safeguarding EU systems amid ongoing cyber threats to critical services and institutions.

“On 30 January, the European Commission’s central infrastructure managing mobile devices identified traces of a cyber-attack, which may have resulted in access to staff names and mobile numbers of some of its staff members.” reads the advisory. “The Commission’s swift response ensured the incident was contained and the system cleaned within 9 hours. No compromise of mobile devices was detected.”

The Commission has not revealed how the threat actors accessed the mobile device management platform.

The European Computer Emergency Response Team (CERT-EU) is investigating the security breach.

Attackers could use the stolen data to launch targeted vishing and phishing attacks by impersonating colleagues or officials to steal credentials. The stolen data enables reconnaissance for spear phishing or physical targeting of key personnel. Finally, GDPR violations and reputational damage undermine the Union’s cyber credibility.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Ivanti EPMM)




文章来源: https://securityaffairs.com/187806/security/dutch-agencies-hit-by-ivanti-epmm-exploit-exposing-employee-contact-data.html
如有侵权请联系:admin#unsafe.sh