A coordinated cyberattack campaign exploiting critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile has successfully compromised multiple European government agencies, exposing sensitive employee data and raising serious concerns about the security of enterprise mobile device management platforms across the public sector.

Dutch Government Institutions Compromised

The Dutch Data Protection Authority and the Council for the Judiciary both fell victim to this exploitation campaign, with their compromise confirmed in correspondence delivered to the Dutch parliament on Friday by Justice Secretary Arno Rutte and Secretary for Kingdom Relations Eddie van Marum. The incident carries particular significance given that one of the affected entities is the nation’s primary data protection regulator, responsible for overseeing privacy compliance across the country.

The National Cyber Security Center received notification from Ivanti on January 29 regarding critical security vulnerabilities affecting EPMM, a comprehensive platform designed to manage mobile devices, applications, content distribution, and associated security controls across enterprise environments. Through their exploitation of these flaws, threat actors successfully obtained access to personal information belonging to employees at both affected agencies, including full names, corporate email addresses, and business telephone numbers. All individuals whose information was potentially accessed have received direct notification of the breach.

In an unusual procedural twist reflecting the sensitive nature of having the data protection authority itself breached, the AP formally reported the incident to its own internal data protection officer, while maintaining operational separation by having different authority staff members conduct the investigation into the parallel compromise affecting the Council for the Judiciary.

European Commission Infrastructure Targeted

The European Commission disclosed that its centralized mobile device management infrastructure exhibited traces of unauthorized access discovered on January 30, 2026. The intrusion potentially exposed staff names and mobile telephone numbers belonging to an undisclosed number of Commission personnel. Demonstrating effective incident response capabilities, the Commission’s security teams successfully contained the breach and completed remediation activities within a nine-hour window from initial detection. Critically, forensic analysis confirmed that the mobile devices themselves remained uncompromised, with the breach limited to the management infrastructure layer.

While the Commission’s public disclosure carefully avoided explicitly identifying Ivanti EPMM as the compromised system, the temporal correlation with other known EPMM compromises and the technical nature of the incident strongly suggest this breach forms part of the same coordinated vulnerability exploitation campaign affecting other European government entities.

Extensive Finnish Government Breach

Finland’s government information and communications technology service provider, Valtori, announced the discovery of a significant breach on January 30, 2026, affecting work-related information belonging to approximately 50,000 government employees. This figure is particularly alarming as it represents nearly two-thirds of Finland’s total central government workforce of approximately 77,000 individuals. The attack specifically targeted Valtori’s mobile device management platform, providing threat actors with access to employee names, work email addresses, business phone numbers, and device identification information.The breach’s scope proved substantially larger than initially assessed, with early estimates suggesting roughly 20,000 devices were affected before subsequent forensic analysis revealed the true scale of the compromise. Investigators uncovered a critical architectural flaw that significantly amplified the breach’s impact beyond currently active users. The mobile device management system employed a soft-delete mechanism rather than permanent data removal, merely marking deleted records as removed rather than completely erasing them from the database. This technical shortcoming meant that historical device and user information belonging to all organizations that had utilized the service throughout its entire operational lifespan remained accessible to attackers, potentially exposing data from organizations that had long since discontinued their use of the platform.

Technical Characteristics of the Exploited Vulnerabilities

Ivanti released security patches on January 29, 2026, addressing two critical code injection vulnerabilities designated as CVE-2026-1281 and CVE-2026-1340. Both vulnerabilities received maximum severity ratings with CVSS scores of 9.8, reflecting their critical nature and ease of exploitation. The flaws specifically affect the In-House Application Distribution functionality and the Android File Transfer Configuration components within EPMM, creating attack vectors that permit completely unauthenticated remote attackers to achieve arbitrary code execution on vulnerable systems without requiring any prior access or credentials.

Ivanti acknowledged that threat actors had already discovered and actively exploited both vulnerabilities as zero-days prior to public disclosure, successfully compromising what the vendor characterized as “a very limited number of customers” before patches became available. The United States Cybersecurity and Infrastructure Security Agency responded swiftly to the threat by adding CVE-2026-1281 to its authoritative Known Exploited Vulnerabilities catalog and mandating that all federal agencies implement appropriate mitigations no later than February 1, 2026.

The threat landscape deteriorated rapidly following disclosure when a functional proof-of-concept exploit demonstrating remote code execution capabilities became publicly available on January 30, 2026. This public release significantly accelerated exploitation activity by lowering the technical barrier for additional threat actors to mount attacks against vulnerable installations.

Widespread Exploitation Activity

Internet-wide scanning conducted by the Shadowserver Foundation identified 86 compromised EPMM instances by Monday afternoon based on observable artifacts indicating successful exploitation. The scale of targeting became more apparent through honeypot telemetry data collected through February 7, 2026, which recorded hundreds of inbound connection attempts originating from more than 130 geographically and operationally distinct IP addresses. Analysis of this traffic revealed that approximately 58 percent of the observed connections represented direct exploitation attempts rather than reconnaissance or scanning activity.

The threat actors representing diverse motivations and origins continue actively compromising additional Ivanti EPMM installations, with evidence suggesting that individual vulnerable systems may have suffered compromise by multiple distinct threat groups exploiting the same vulnerabilities independently.

Historical Context and Recurring Targeting

The current compromise campaign represents merely the latest in an established pattern of zero-day exploitation targeting Ivanti EPMM. Previous notable incidents include the exploitation of CVE-2023-35078 during 2023 and a sophisticated attack chain leveraging CVE-2025-4427 in combination with CVE-2025-4428 during 2025. This recurring victimization pattern firmly establishes EPMM as a persistent high-value target preferred by advanced threat actors seeking to compromise enterprise mobile device management infrastructure.

Current Remediation Limitations and Future Fixes

Ivanti has made interim RPM-based patches available for affected EPMM versions, though these emergency fixes suffer from a significant limitation that complicates patch management. The interim patches do not persist through version upgrades, requiring administrators to manually reapply them following any software updates to the EPMM platform. Organizations must therefore implement procedures to track and reapply these temporary fixes after routine maintenance activities until a permanent solution becomes available.

A comprehensive and persistent fix is scheduled for inclusion in EPMM version 12.8.0.0, which Ivanti has committed to releasing during the latter portion of the first quarter of 2026. Organizations currently dependent on interim patches will need to maintain heightened vigilance and strict patch reapplication procedures throughout this transitional period.

An additional concerning dimension of the threat involves the architectural relationship between EPMM and Ivanti Sentry gateway products. Although the Sentry gateway itself contains no directly exploitable vulnerabilities related to this incident, EPMM appliances maintain privileged command execution capabilities over associated Sentry gateways by design. This architectural trust relationship creates a lateral movement opportunity whereby threat actors who successfully compromise an EPMM deployment can leverage those elevated privileges to pivot and subsequently compromise connected Sentry gateway infrastructure, potentially expanding their access beyond the initially compromised mobile device management layer.

Strategic Implications

This coordinated campaign demonstrates how sophisticated threat actors systematically identified and exploited zero-day vulnerabilities within mobile device management infrastructure protecting multiple European government organizations. The attackers initiated their campaign before patches became available and sustained their exploitation activity even after public disclosure and patch availability, suggesting well-resourced and persistent adversaries with strategic objectives extending beyond opportunistic data theft. The pattern of targeting government institutions across multiple nations indicates coordinated reconnaissance, capability development, and operational execution characteristic of advanced persistent threat actors rather than common cybercriminals.

References: