Belgian State Security (VSSE) staff data exposed via Ivanti EPMM flaws
Belgium's civilian intelligence service, the State Security Service (VSSE), was found to have been breached through vulnerabilities in Ivanti Endpoint Manager Mobile between May 2025 and spring 2026, exposing names, phone numbers and email addresses of its personnel; classified systems were not reached.
- Victim
- Belgian State Security Service (VSSE)
On 20 June 2026, Belgian broadcasters RTBF and VRT NWS reported that the State Security Service (VSSE, Staatsveiligheid / Sûreté de l'État), Belgium's civilian intelligence agency, had suffered a cyberattack in which attackers obtained personal data of its staff. VRT confirmed the story through independent sources; the VSSE itself declined to comment. The intrusion was discovered during an inspection of the agency's IT infrastructure.
Attackers had exploited vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), the mobile device management software the VSSE uses to manage service phones and control access rights. The exposure period ran from roughly May 2025 to spring 2026. Data reached included names, phone numbers and email addresses of VSSE personnel and possibly of external contacts; Ivanti has said the same flaws can also expose device identifiers and GPS data.
What was not affected
According to sources close to the investigation, the attackers did not gain access to the internal systems that process confidential and classified information. The Centre for Cybersecurity Belgium advised password changes and system updates.
Attribution and context
No formal attribution has been made. Security firms have linked exploitation of these Ivanti EPMM vulnerabilities to UNC5221, a cyber-espionage cluster with suspected Chinese ties, and the same flaws were previously tied to incidents at the European Commission, the Dutch judiciary and the Dutch Data Protection Authority. This is the second known breach of the VSSE: Belgian prosecutors earlier investigated suspected Chinese state-backed hackers who stole about 10% of the agency's email traffic between 2021 and 2023 through a Barracuda email security flaw.
Why it matters
For an intelligence service, even "unclassified" metadata is sensitive: staff names, phone numbers, contacts and potentially device locations help an adversary map an agency's structure and identify its officers. The case also shows how mobile device management platforms, which sit at the center of an organization's phone fleet, have become a high-value target for state-sponsored espionage across European governments.
Timeline
RTBF and VRT NWS report that VSSE personnel data was exposed; the agency declines to comment.
Further reporting details that the breach stemmed from Ivanti Endpoint Manager Mobile flaws and did not reach classified systems.
Sources
- vrt.behttps://www.vrt.be/vrtnws/nl/2026/06/20/staatsveiligheid-cyberaanval/
- techzine.euhttps://www.techzine.eu/news/security/142341/belgian-state-security-hit-by-ivanti-data-breach/