The Council of Europe ShinyHunters data breach investigation is now the center of a story that mixes specific numbers with an unverified claim. A hacking group calling itself ShinyHunters says it stole hundreds of thousands of documents from the Council of Europe's HR and payroll systems. The Council of Europe has confirmed it is investigating the claim. That is where the certainty currently ends.
What ShinyHunters actually claims
According to breach-tracking reports from the weekend the claim surfaced, ShinyHunters says it took more than 429,000 documents from multiple Council of Europe departments.
- More than 409,000 payslips covering over 10,000 staff, spanning 2011 to 2026
- Over 3,700 in-house personnel files
- More than 14,000 CVs
- Other files said to include names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, tax and Social Security information, and medical data
If accurate, this would be a serious breach affecting current and former staff of one of Europe's oldest intergovernmental bodies. The scale and detail in the claim are alarming, but they are not the same as verification.
What "under investigation" means
Reporting on the incident describes the Council of Europe as investigating the ShinyHunters claims. Confirming a breach of this size involves checking access logs, identifying which systems were touched, and matching sample data against real records. None of that happens in a day, and institutions rarely announce results the same week a claim appears.
Until that work is done and communicated, the honest description of this story is "claimed", not "confirmed". Extortion groups have a financial incentive to exaggerate scope, inflate figures, or claim data they do not fully hold, because attention and pressure are part of how extortion works.
A useful comparison: how a confirmed breach reads differently
Look at how a separate, confirmed case involving the same group unfolded. Instructure disclosed that it had suffered a cybersecurity incident and was working with outside cybersecurity experts and law enforcement to investigate it. A day later, the company issued an update confirming that personal information, including names, email addresses, student ID numbers, and internal messages, had actually been exposed.
That sequence is what confirmation usually looks like: the organization's own disclosure, cooperation with investigators, and a specific, narrowed description of what was really exposed. A claim from the attacker alone, without that sequence, is a starting point for scrutiny, not a conclusion.
Why breach claims spread the way they do
Groups like ShinyHunters often post claims on leak forums that exist on both the open web and Tor hidden services, sometimes attaching sample data to pressure a victim into paying or to build reputation among other criminals. Journalists and researchers monitor these posts, which is often how the public hears about an alleged breach before the named organization says anything at all.
This is where dark-web literacy matters. Browsing a criminal leak forum through Tor Browser does not make you a source of truth, and it proves nothing about whether the underlying data is real, complete, or current. Tor routes your traffic through relays but does not verify claims. It does not make anything you do there automatically anonymous.
What to do if you might be affected
If you work or have worked for the Council of Europe, or you handle HR data for an organization named in a similar claim, treat the report seriously without treating it as settled fact.
- Watch for official communication from the Council of Europe rather than relying on social media summaries of the claim
- Be alert to phishing that references payslips, tax records, or HR details, since leak-sounding specifics make convincing bait
- If you need to report a security concern or share sensitive documents with journalists, use a tool such as SecureDrop, which exists for sources to do that without exposing their identity through ordinary email
- Consider a privacy-respecting provider like Proton Mail for sensitive correspondence and a non-tracking search engine like DuckDuckGo when researching the story
How to verify a breach claim yourself, safely
Do not go looking for "the Hidden Wiki" to hunt for leaked data or to try to verify a claim. What runs under that name today is a shifting collection of clones and copycats, many stuffed with outdated, fake, or genuinely harmful links. It is not a directory you can trust, and it never verifies anything for you.
If an organization you already deal with, such as a bank, employer, or public body, publishes an onion address for a reporting or support channel, get that address from the organization's own official surface-web page and check it against resources such as the Tor Project's own guidance on using Tor Browser safely. A familiar name attached to an onion address is never, on its own, proof of legitimacy.
The Council of Europe ShinyHunters data breach investigation is still open. The figures ShinyHunters cites are specific enough to take seriously and unverified enough to withhold judgment on. That gap between a criminal's claim and an institution's confirmation is exactly where careful reporting and careful readers matter most.