Skip to content
EspionageContained

Belgian State Security (VSSE) staff data exposed via Ivanti EPMM flaws

Belgium's civilian intelligence service, the State Security Service (VSSE), was found to have been breached through vulnerabilities in Ivanti Endpoint Manager Mobile between May 2025 and spring 2026, exposing names, phone numbers and email addresses of its personnel; classified systems were not reached.

Victim
Belgian State Security Service (VSSE)

On 20 June 2026, Belgian broadcasters RTBF and VRT NWS reported that the State Security Service (VSSE, Staatsveiligheid / Sûreté de l'État), Belgium's civilian intelligence agency, had suffered a cyberattack in which attackers obtained personal data of its staff. VRT confirmed the story through independent sources; the VSSE itself declined to comment. The intrusion was discovered during an inspection of the agency's IT infrastructure.

Attackers had exploited vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), the mobile device management software the VSSE uses to manage service phones and control access rights. The exposure period ran from roughly May 2025 to spring 2026. Data reached included names, phone numbers and email addresses of VSSE personnel and possibly of external contacts; Ivanti has said the same flaws can also expose device identifiers and GPS data.

What was not affected

According to sources close to the investigation, the attackers did not gain access to the internal systems that process confidential and classified information. The Centre for Cybersecurity Belgium advised password changes and system updates.

Attribution and context

No formal attribution has been made. Security firms have linked exploitation of these Ivanti EPMM vulnerabilities to UNC5221, a cyber-espionage cluster with suspected Chinese ties, and the same flaws were previously tied to incidents at the European Commission, the Dutch judiciary and the Dutch Data Protection Authority. This is the second known breach of the VSSE: Belgian prosecutors earlier investigated suspected Chinese state-backed hackers who stole about 10% of the agency's email traffic between 2021 and 2023 through a Barracuda email security flaw.

Why it matters

For an intelligence service, even "unclassified" metadata is sensitive: staff names, phone numbers, contacts and potentially device locations help an adversary map an agency's structure and identify its officers. The case also shows how mobile device management platforms, which sit at the center of an organization's phone fleet, have become a high-value target for state-sponsored espionage across European governments.

Timeline

  1. RTBF and VRT NWS report that VSSE personnel data was exposed; the agency declines to comment.

  2. Further reporting details that the breach stemmed from Ivanti Endpoint Manager Mobile flaws and did not reach classified systems.

Sources

  1. vrt.behttps://www.vrt.be/vrtnws/nl/2026/06/20/staatsveiligheid-cyberaanval/
  2. techzine.euhttps://www.techzine.eu/news/security/142341/belgian-state-security-hit-by-ivanti-data-breach/

Related incidents

EspionageResolved

MINDEF I-net breach

A targeted intrusion into Singapore's Ministry of Defence I-net web-surfing system stole the NRIC numbers, phone numbers and birth dates of 850 national servicemen and staff in the country's first publicly disclosed breach of a government defence network.

Victim
Singapore Ministry of Defence (MINDEF)
Records
850
EspionageContained

UNC6508 PRC-nexus medical & defense research espionage campaign

Google's Threat Intelligence Group disclosed that PRC-nexus actor UNC6508 spent more than a year inside U.S. and Canadian medical, academic and military-health research environments, compromising legacy REDCap servers, deploying custom INFINITERED malware and abusing Google Workspace email compliance rules to silently exfiltrate research and defense data.

Victim
U.S. and Canadian medical, academic and military-health research institutions