Wednesday , May 14 2025
Europol

CYBERSECURITY AND DATA PROTECTION
Serious security breach hits EU police agency

They were supposed to be under lock and key, in a secure storage room deep inside Europol’s headquarters in The Hague.

But a clutch of highly sensitive files containing the personal information of top law enforcement executives went missing last summer. Europe’s law enforcement agency has been mired in a whodunit ever since.

CVSS 10.0 Flaw
Critical flaw in Siemens OZW Web Servers Enable Unauthenticated RCE

Siemens issued a security advisory (SSA-047424) for two serious vulnerabilities—CVE-2025-26389 and CVE-2025-26390—impacting the OZW672 and OZW772 web servers. These servers...
Read More
CVSS 10.0 Flaw  Critical flaw in Siemens OZW Web Servers Enable Unauthenticated RCE

Microsoft Patch Tuesday May 2025: 72 flaws, 5 Actively Exploited Zero-Day

Microsoft has released its Patch Tuesday updates for May 2025, addressing a total of 78 vulnerabilities across its product ecosystem,...
Read More
Microsoft Patch Tuesday May 2025: 72 flaws, 5 Actively Exploited Zero-Day

OTP glitch disrupted NID services across the country

NID services in Bangladesh are temporarily suspended due to issues with delivering One-Time Passwords (OTP) needed to access the NID...
Read More
OTP glitch disrupted NID services across the country

Google to pay Texas $1.4 billion for location tracking practices

Google will pay about $1.4 billion to Texas to settle two lawsuits regarding location tracking and biometric data storage without...
Read More
Google to pay Texas $1.4 billion for location tracking practices

YouTube geo-blocks at least 4 Bangladeshi TV channels in India

YouTube has restricted access to at least four Bangladeshi television channels in India following a takedown request from the Indian...
Read More
YouTube geo-blocks at least 4 Bangladeshi TV channels in India

Microsoft Patches Four Critical Azure and Power Apps Vulns

Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
Microsoft Patches Four Critical Azure and Power Apps Vulns

Qilin Ransomware topped April 2025 with 45+ data leak disclosures

The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
Qilin Ransomware topped April 2025 with 45+ data leak disclosures

SonicWall Patches 3 Flaws in SMA 100 Devices

SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
SonicWall Patches 3 Flaws in SMA 100 Devices

Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

According to an internal agency note seen by POLITICO, and conversations with current and former staff, the hardcopy personnel files of Europol Executive Director Catherine De Bolle and other senior officials leaked sometime before September.

“On Sep. 6, 2023, the Europol Directorate was informed that personal paper files of several Europol staff members had disappeared,” read the note. When officials checked all the agency’s records, it discovered “additional missing files,” it added.

The incident has been the talk of the agency based in The Hague, with staff exchanging notes over how the files went missing — and, above all, trying to figure out how Europe’s central law enforcement authority got itself into such a mess.

“Given Europol’s role as law enforcement authority, the disappearance of personal files of staff members constitutes a serious security and personal data breach incident,” the note, shared on its internal message board system and dated Sep. 18, said.

Europol is one of the European Union’s largest agencies. It coordinates major international investigations and operations with national police authorities and partners like Interpol and the United States’ FBI.

POLITICO spoke to four current and former officials of Europol with knowledge of the incident. Some of the lost files reappeared when a citizen found them abandoned in a public place in The Hague and brought them to a local police station, the four officials said.

It wasn’t immediately clear how long they’d been missing nor why they’d been taken from inside the institution, they said.

In response to POLITICO’s questions, The Hague’s police force spokesperson Steven van Santen said: “The Hague Police was involved in some details connected to an ongoing internal Europol investigation.”

The personnel files were those of Europol’s Executive Director De Bolle and three of her deputy directors, Jürgen Ebner, Andrei Lințǎ and Jean-Philippe Lecouffe, three of the four officials said.

Human resources files can contain information about the job application of the official, relevant training, birth dates, marriage status, dependents, current address and other regular information stored by HR, one of the officials said.

Following the incident, the head of Human Resources at the agency, Massimiliano Bettin, was placed on administrative leave, the four officials said.

Europol’s internal note said that, “against this background, the head of the HR unit [Bettin] will not be available until further notice” and “the head of the administration department will ensure business continuity for the management of the HR unit.”

An email sent by POLITICO to Bettin’s Europol email address received an automatic response, which reads “thank you for your message, I am not available. I have no access to my mails.” Bettin’s LinkedIn page said he was “actively applying” for a new job.

In a statement to POLITICO, Bettin said he could not comment on the case.

Europol’s sensitive hardcopy HR files are kept locked away in a safe, in a room that is limited to restricted personnel. Very few people know the code to the safe, one of the officials who had direct knowledge of the procedure said. It is unclear how the files were taken.

Bettin, who served as chief marshal in Italy’s police forces, had been the head of HR at Europol since 2016. The agency has a total of more than 1,400 staff.

One theory is that the files could have been taken to damage Bettin, in the context of internal conflicts within the agency, according to officials.

The European Data Protection Supervisor (EDPS) was also notified of the incident, as were the staff members whose files were affected, the internal note said. In a statement to POLITICO, the EDPS said it could not comment “at this stage on ongoing cases.”

Europol’s press office declined to comment on POLITICO’s questions, saying it was “not in a position to comment” on internal matters.

Source: Politico

Check Also

Play Ransomware

CVE-2025-29824
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an …

Leave a Reply

Your email address will not be published. Required fields are marked *