The European Court of Auditors has found significant gaps in the EU’s ability to coordinate its response to major cybersecurity incidents, particularly when sharing timely and actionable information between national and EU-level organizations.
The audit found that cooperation between two key cyber response networks has still not been formally defined, while differences in national security laws and implementation of the NIS2 Directive can hinder information sharing. The European Cybersecurity Alert System was also not operational at the time of the audit, with two security hubs delayed by procurement issues and key cooperation agreements, technical standards and classification systems still missing.
Auditors also identified overlapping responsibilities among EU cybersecurity bodies and weaknesses in checks on organizations receiving EU cybersecurity funding. The findings come despite €1.4 billion being allocated to cybersecurity through the EU’s Digital Europe Programme for 2021–2027.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Critical infrastructure crosses borders faster than authority does. A state-backed attacker can probe the same router or remote-access service across energy, transport, healthcare, telecoms, and water. The first defender to see the intrusion needs a way to warn every operator running the same technology.
“The European Court of Auditors’ audit shows why that warning can stall. National response teams, EU-CyCLONe, and the European Union Agency for Cybersecurity operate across different security laws, NIS2 implementations, classifications, and mandates. During an active incident, a technical warning becomes a permissions problem.
“CISA’s Automated Indicator Sharing moves machine-readable indicators and defensive measures in real time. The Joint Cyber Defense Collaborative adds playbooks and rapid exchanges across government, industry, and international partners. Europe needs those functions tied to its existing institutions, with shared rules for confidence, urgency, and action.
“I would measure the investment by one clock, the time between an energy operator seeing a state-backed probe and every similarly exposed operator receiving something usable. Every unresolved permission is attack surface.”
John Strand, Owner, Black Hills Information Security:
“There is absolutely nothing about this report that surprises me. It really doesn’t matter what type of organization you’re dealing with. It could be nation-states trying to coordinate during an incident, or internal security teams working inside the same company. You’re going to see the same communication gaps, overlaps, and confusion.
“My recommendation is simple. Drill. Run incident response tabletop exercises regularly. Keep them terse. Keep them quick. Don’t make them overly complicated. Run multiple scenarios specifically designed to expose where communication starts to break down.
“Then document those gaps and build a plan of action and milestones to fix them. Communication problems during an incident aren’t unusual. I would expect to find them in almost any organization. The important question is whether you find them during an exercise or during a real incident.”
Seemant Sehgal, Founder & CEO, BreachLock:
“The audit findings track with a pattern that shows up in a lot of large organizations trying to coordinate incident response across independent teams. Frameworks describe how the handoffs should work, but during a live incident, the seams where responsibilities were never clearly assigned are where delays happen, and 1.4 billion euros in funding does not close that gap on its own if the operational agreements underneath it are still being negotiated.
“The useful question is whether the ECA report will apply enough pressure to get the European Cybersecurity Alert System operational and to define those handoffs before the next major incident, rather than during one.”
Co-ordinating any sorts of incidents is key to bringing them under control quickly. And if anyone has the will to do it, the EU does. So I hope that they don’t prove me wrong.

FBI pwned by ShinyHunters
Posted in Commentary with tags FBI on September 22, 2026 by itnerdIt’s been reported today that threat actor group ShinyHunters have said to 404 Media via the story ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees:
A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.
The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.
“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.
Denis Calderone, CTO, Suzu Labs Had This To Say:
“ShinyHunters has spent the last week picking fights. On Friday they took over Cl0p’s leak site and put up a ‘seized by ShinyHunters’ banner, and by Tuesday the same banner was on the FBI’s jobs portal. Both were framed as payback, one for threats from a rival gang and one for an FBI advisory that told victims not to pay them. The FBI hasn’t confirmed anything yet, but if this holds up, it doesn’t look like the ShinyHunters we’ve been seeing all year. Their model has always been breach, extort, then settle or leak, and that only works when the victim can pay. The FBI isn’t going to pay, and it isn’t going to pull an advisory because a criminal group demanded it. Not sure what’s going to happen in a week, but I seriously doubt the FBI will act on this threat.
“They also say this isn’t financially motivated, but I’d take that with a grain of salt. I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.
“That zero-day is where everyone else should focus, since ShinyHunters says they plan to use it more broadly. If you run PeopleSoft, don’t wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren’t reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”
“Limiting your blast radius is the best precautionary play here.”
If the FBI did get pwned, then that’s a hell of a black mark on the FBI. You have to wonder what the FBI has to say about that. Let’s see if they dare to comment.
Leave a comment »