Home All Breaches mercer_didnt_pay_the_ransom_shinyhunters.7z

mercer_didnt_pay_the_ransom_shinyhunters.7z

Database World ROC

This page documents a data breach listing tracked by Breach House. It summarizes the publicly advertised leak attributed to Database World ROC, including the affected entity, origin and the date the listing was first indexed.

Country
Discovered
2026-08-08
Breach ID
a1bf41b6d0a0

Breach Overview

Data said to have been published by ShinyHunters from a breach of the Council of Europe, an international organization based in Strasbourg. ShinyHunters claimed the attack on 14 June 2026 and published roughly 295 GB across about 430,000 files on 18 June 2026 after a ransom deadline passed unpaid, via an unauthenticated Oracle PeopleSoft zero-day (CVE-2026-35273). Exposed material spans HR, General Secretariat, PACE and EDQM records, including about 409,000 pay slips for over 10,000 staff (2011-2026), CVs, HR documents, and banking/tax information.

Dark Web Exposure

Cross-referenced against HaveIBeenRansom's dark-web index of ransomware leaks, breaches & infostealer logs.
0
found in Infostealer logs
0
found in Traditional breaches
0
found in Ransomware leaks
Emails exposed
••••
Internal
•••
External
•••
Distinct leaks
••
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
Full exposure is locked
See every breached email, the internal-vs-external split and each leak source behind this breach.
Want the complete picture — passwords, machines, full leak files? It's all searchable on HaveIBeenRansom.
Search this breach →
Original Post View Group: Database World ROC
Legal Disclaimer: This breach record is compiled from publicly advertised leak listings. Breach.house only records what the operators themselves publish in the open. We take screenshots of their public pages and keep the proof material they post there, so that a listing can be verified and its status tracked over time. We do not purchase data, we do not solicit or encourage its publication, we do not access any private system, and we do not alter anything we record. Nothing is offered for download here, and detailed content is not published on this page or anywhere else on the public site: access to it is restricted to vetted customers under contract, for incident response, due diligence and cyber-resilience work. Breach.house is not affiliated with, and does not act on behalf of, the operators who publish this material. If you represent an organisation or individual named here and want a record reviewed or removed, contact us and we will act on it.