2024-05-13
Europol is Investigating Alleged Breach of Law Enforcement Info Sharing Portal
Europol is investigating a threat actors claims that they stole data from the Europol Platform for Experts (EPE), a collaborative platform for law enforcement for sharing best practices and other information. EPE has been offline since Friday, May 10. A Europol spokesperson has told multiple news sites that they are aware of the incident and [are]assessing the situation.
Editor's Note
The attacker seems to have accessed a test environment using their Zscaler proxy to access production data. With efforts tied to ZTA such as Zscaler facilitating access to internal systems, it's more important than ever to make sure that you have the same bar on access control, particularly authentication, to your non-production environments. While we could argue that dummy data should be used outside production, there are valid use cases for real data for acceptance testing or other activities, it makes sense to implement the same security on all platforms for such use cases.
Lee Neely
Read more in
Security Week: Europol Investigating Breach After Hacker Offers to Sell Classified Data
The Register: Europol confirms incident following alleged auction of staff data
Dark Reading: IntelBroker Nabs Europol Info; Agency Investigating
Bleeping Computer: Europol confirms web portal breach, says no operational data stolen