Unpacking the Recent Cybersecurity Breaches Linked to Ivanti
On February 10, 2026, significant cybersecurity concerns were highlighted as the Dutch Data Protection Authority (AP) and the Council for the Judiciary confirmed that their systems were compromised due to vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM). The alarming news reached the parliament amidst an increasing number of data breaches impacting European institutions, raising questions about the security of mobile device management systems and the protocols in place to protect sensitive data.
A Closer Look at the Vulnerabilities
The incident began on January 29 when the National Cyber Security Center (NCSC) was informed of vulnerabilities in the EPMM. This system is crucial for managing mobile devices, apps, and content securely. Reports indicated that unauthorized individuals accessed sensitive information, including work-related data of AP employees—specifically names, email addresses, and phone numbers. The breach highlights a significant failure in data protection protocols, shedding light on the urgency of improving cybersecurity measures across organizations relying on similar technologies.
Broader Implications for the European Commission
The situation escalated further when the European Commission reported traces of a cyber attack on its infrastructure responsible for managing mobile devices. While they contained the incident within nine hours and confirmed no mobile device compromise, the potential exposure of employee names and mobile numbers raised eyebrows. The urgency was palpable, as the Commission stated its commitment to safeguarding internal systems and monitoring potential threats closely.
Finland’s Disturbing Disclosure
Adding to the alarming trend, Finland’s state information and communications provider, Valtori, disclosed that a data breach had exposed the work-related details of approximately 50,000 government employees. This breach, discovered on January 30, 2026, was linked to a zero-day vulnerability in EPMM. Even though Valtori implemented a corrective patch on the same day Ivanti released updates for serious identified vulnerabilities, the fact that sensitive data was compromised is troubling.
The Exploit and Its Consequences
The vulnerabilities in question pertained to identified Remote Code Execution flaws (CVE-2026-1281 and CVE-2026-1340) with CVSS scores of 9.8, indicating a critical level of severity. Attackers exploited these weaknesses, allowing them to gain unauthorized access to sensitive information that facilitated the operation of EPMM services. Interestingly, reports revealed that the management system failed to permanently delete removed data; instead, it only marked the data as deleted. This oversight raises major concerns about data retention and exposure risks in organizational systems.
Insights from Industry Experts
Industry insiders have weighed in on this unfolding situation. watchTowr CEO Benjamin Harris emphasized that these attacks are not random acts of opportunism but rather the work of highly skilled and resourceful actors executing a targeted campaign. His assertion underscores the need to reevaluate how organizations perceive their internal systems. Anything deemed “internal” or “safe” should now be scrutinized more closely, as attackers are increasingly targeting these deeply embedded systems.
Moreover, Harris pointed out that in today’s rapidly evolving cyber landscape, resilience is as crucial as prevention. The speed with which an organization can identify anomalies, validate weaknesses, and contain damage can often determine whether an incident escalates into a full-blown crisis.
A Coordinated Approach to Cyber Threats
The coordinated attacks targeting European government institutions coincide with a strategy that appears to exploit EPMM installations for long-term access. Following the initial compromises, attackers are believed to have uploaded dormant payloads into systems, creating pathways for future exploitation. Notably, a dormant in-memory Java class loader was deployed, waiting for specific trigger parameters to activate. This method reflects sophisticated tactics characteristic of initial access brokers aiming to secure footholds within systems for later use.
The Need for Advanced Security Measures
As cybersecurity threats grow more sophisticated, the incidents linked to Ivanti EPMM serve as a stark reminder of the critical need for advanced security measures. Organizations must prioritize enhancing their cybersecurity frameworks to address vulnerabilities effectively, especially in systems as pivotal as mobile device management. Ongoing vigilance, regular updates, and a culture of resilience will be essential as we navigate this increasingly complex digital landscape.
By understanding the nuances of these breaches, organizations can take proactive steps to fortify their defenses and protect sensitive information from becoming the next casualty in the escalating battle against cybercrime.

