By Graham Jarvis – Freelance Business and Technology Journalist

One thing is worth remembering: nobody is immune to either fraud or data breaches. Each and every one of us – including our organisations – could be successfully cyber-attacked; and this is exactly what happened recently in late May and early June 2026 to the Council of Europe. Attacks often begin with an emotional hook because when we as individuals become emotional, we think irrationally. This leads to mistakes begin made. In this case, the alleged emotional and structural hook was the 297GB exfiltration of the organisation’s payroll and medical records.
It reveals a terrifying reality: The very institutions tasked with governing privacy and human rights are helpless against modern cloud extortion – not even from hacking group ShinyHunters. This group executed the compromise via a sophisticated zero-day supply chain exploitation, rather than via a traditional perimeter hack. This poses a systemic threat because it emphasises the risk that, potentially, many organisations can no longer sit comfortably thinking that they can still protect their border.
Zero-day exploit
This culminated in the Oracle PeopleSoft zero-day, whereby the hackers exploited vulnerabilities, such as being able to create a Server-Side Request Forgery (SSRF), an unauthenticated Remote Code Execution (RCE) flaw in the Environment Management component of PeopleSoft PeopleTools, versions 8.61 and 8.62.
This impacted at least 100 organisations globally – including the Council of Europe, with a heavy focus on the higher education sector (such as the University of Nottingham) and corporate networks. For remediation, Oracle issued an emergency security alert with mitigation and patching instructions on 10th June 2026. Five days later, and The Register confirmed in an article that the ShinyHunters extortion group had added the international organisation to its dark web leak site. Therefore, the Council of Europe fell victim to the very same CVE-2026-35273 PeopleSoft heist.
Eventually, ShinyHunters got to a point where they were able to safely pull data from the Council of Europe’s servers, and list it on their Tor leak site over the weekend of 13th and 14th June 2026. It was at this point they put forward a demand for a hard ransom negotiation deadline of 16th June 2026. The Council of Europe refused to negotiate an undisclosed amount as part of a ransom, and so they leaked 4.7 GB of compressed data dump on 18 June 2026 to prove the validity of their haul. Despite this being part of a multi-stage release of the stolen data, the Council has continued to refuse to pay.
Technical turning point
The hack has nevertheless highlighted a technical turning point – and much because it caught so many organisations off-guard. Subsequently, it demonstrates that the traditional patch and pray approach to cyber-security defence models are completely fractured. To this end, there is a massive and unfolding cyber-security crisis that needs to be immediately challenged and tackled.
Organisations need to avoid this chaos. In another incident, ShinyHunters defaced Canvas login portals during the final exams at 330 schools – illustrating how digital extortion is in this case about inflicting immediate real-world disruption on millions of students and educators. While this is likely to cause much emotional stress on all of them, sometimes these events are about causing stress to push an organisation or an individual to make a mistake for financial gain.
Thankfully, Canadian firm Telus Digital did not pay the $65m demanded by the group. However, it shows that cybercrime has gone way beyond being an operational nuisance. It is a material threat to corporate solvency and, particularly when data breaches are involved. In some jurisdictions, such as in the EU and in the UK, it can lead to heavy fines in line with GDPR regulatory breaches. So, their exploits still pose a threat to global infrastructure, education and governance.
Entirely in the Cloud

As David Trossell, CEO and CTO of WAN Acceleration company Bridgeworks, says, “The World operates entirely in the Cloud in mid-2026, and this makes the software supply chain the ultimate vulnerability for any organisation; this allows for hackers to cause an intersection of sophisticated state-level disruption, corporate liability and to exploit the vulnerabilities of everyday public, civic and educational institutions inasmuch as those of corporate entities.”
Given that the threat from groups such as ShinyHunters comes from SaaS exploits and from cloud supply chain breaches, there is a role for WAN Acceleration to either eliminate or reduce the disruption caused by data breaches.
“Rather than acting after the fact, it’s important to store data in at least 3 far-off, disparate locations to minimise any disruption and to maintain uptime by focusing on service continuity,” he advises. This is because prevention is always cheaper than a cure – or than moving the corporate battle towards containment, rapid detection and post-datum recovery.
Trossell argues that it’s no good accepting the death of any permitter when it comes to cyber-security and preventing data breaches. The goal is to protect data, and even if a breach is exfiltrated it must still be highly encrypted. Unlike WAN Optimisation, WAN Acceleration, data is encrypted in transit. There is no need, unlike with WAN Optimisation, to unlock the data before it can be sent over a Wide Area Network (WAN). In contrast, WAN Acceleration with PORTrockIT deploys a no-touch approach and its use of artificial intelligence and machine learning can accelerate the transfer of data, while obfuscating cyber-criminals by making it harder to divert and access data in transit.
Maintain continuous, automated offsite replication
By mitigating latency and maximising bandwidth utilisation by up to 98%, enterprises can maintain continuous, automated offsite replication. They can frequently push immutably isolated or air-gapped data to distant, secure facilities. If a breach happens, recovery could – for example – be achieved in two hours old rather than two days because WAN Acceleration achieves up to 50× faster data recovery performance by dramatically shortening the recovery window.
Organisations should nevertheless treat the events caused by cybercriminals, such as ShinyHunters, as a warning that resilience can no longer depend on perimeter security, delayed patching or a reactive incident response. They need to be far more proactive to prevent and curtail any form of cyber-disruption. This begins with assuming that SaaS platforms, cloud services and third-party software supply chains may be at any point compromised.
Mihai Popa, CISO at Bridgeworks, explains: “The lesson from these incidents is that organisations can no longer plan for a world where the perimeter holds. SaaS, cloud platforms and software supply chains are now part of the attack surface, which means resilience has to be engineered into the way data is protected, replicated and recovered. At Bridgeworks, our focus is on helping organisations to keep encrypted data moving securely and rapidly across distance, so that even when disruption occurs, recovery is measured in hours rather than days.”
This warrants, not just WAN Acceleration, but also the prioritisation of continuous monitoring, rapid and continuous vulnerability management, strong identity controls, heightened data encryption, immutable backups stored in geographically dispersed locations that are regularly tested for replication and recovery. At the very least, such plans have to be in place.
Essential: Act to disrupt hackers
In terms of prevention, the goals should be to cut any cyber-attackers ability to disrupt operations before any such event can occur. It is also imperative to have processes in place to ensure that any pressure put on anyone by hackers, doesn’t lead to a decision that could be costly financial and operationally.
Nobody should be given the tools to exploit any individual or organisation, and so they should be taken out of their hands. This is why WAN Acceleration is significant – supporting the practical side of resilience; this is by enabling organisations to move voluminous amounts of highly encrypted data fast across large distances without being impinged by the effects of latency and packet loss.
In a threat landscape where downtime, data loss and delayed recovery can be as damaging as the breach itself. However, with this technology, organisations can shift from a purely defensive posture to one focused on continuity, prevention and, when a beach does occur, it can help with rapid recovery. This posture therefore revives the perimeter and it can prevent its ultimate death.
Graham Jarvis is the Freelance Lead Journalist, for Business and Technology, at Trudy Darwin Communications.







Recent Comments