Ivanti EPMM under pressure: cyberattacks hit European institutions across countries
The National Cyber Security Centre was informed of the situation on 29 January after a vendor warned of serious vulnerabilities in the EPMM system, which is used to manage mobile devices, applications and security policies.

European institutions and government agencies are dealing, within a short period, with a series of cyber incidents that are being linked to critical vulnerabilities in the Ivanti Endpoint Manager Mobile (EPMM) mobile device management system. The impacts have been confirmed by authorities in the Netherlands, Finland and the European Commission.
A common denominator of the incidents is the possible access by attackers to employees' work contact details, not to communications or content on the mobile devices themselves.
Nizozemsko: zasažen úřad pro ochranu osobních údajů i justice
The Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr) informed parliament that their systems were hit by a cyberattack. According to an official statement, there was unauthorised access to employees' work data, specifically names, work email addresses and telephone numbers.
The National Cyber Security Centre was informed of the situation on 29 January after a vendor warned of serious vulnerabilities in the EPMM system, which is used to manage mobile devices, applications and security policies.
The method of intrusion has not been published in detail, however the incident is in the security community associated with recently disclosed flaws in Ivanti EPMM.
Evropská komise: stopy útoku, rychlá izolace
The European Commission stated that its central infrastructure for mobile device management recorded signs of a cyberattack that may have led to access to the names and mobile phone numbers of some staff members.
The Commission emphasised that the incident was isolated and resolved within nine hours of detection and that no compromise of the mobile devices themselves or their content was found. The situation continues to be monitored and further preventive measures have been taken.
Although no specific vendor was officially named, the attack is temporally and technically linked to a campaign targeting Ivanti EPMM vulnerabilities.
Finsko: až 50 000 dotčených zaměstnanců státu
The most extensive impacts were reported by Finland. The state ICT service provider Valtori announced a leak of work data for up to 50,000 public sector employees. The incident was identified on 30 January 2026 and targeted a previously unknown vulnerability (zero-day) in the mobile device management system.
According to published information, an attacker may have gained access to:
- users' names,
- work email addresses,
- telephone numbers,
- technical details about managed devices.
Valtori also stated that data stored directly on mobile devices were not compromised. The investigation, however, revealed a serious issue with handling historical data – according to available findings the system did not permanently erase data after deletion, but only marked it as deleted. This means data of organisations that had previously used the service could also have been exposed.
Kritické zranitelnosti v Ivanti EPMM
Ivanti issued security updates on 29 January 2026 for two critical vulnerabilities:
- CVE-2026-1281
- CVE-2026-1340
Both flaws have a CVSS 9.8 score and allow unauthenticated remote code execution (RCE). Ivanti confirmed that at least one of these vulnerabilities was actively exploited in real attacks, and the security community considers both to be highly critical.
Proč je tento případ zásadní
These incidents again show that:
- mobile device management systems are a high-value target,
- zero-day vulnerabilities are becoming a common part of attacks on state infrastructure,
- issues with data retention and deletion can significantly increase the impact of an attack even long after the fact.
Although in all described cases it was "only" work contact details, the scale of the incidents and their simultaneous occurrence across Europe confirm that the security of MDM/EMM platforms is among the critical points of modern state IT infrastructure.