A third party was on the access path or holding the data in all six European public-sector and critical-infrastructure disclosures this week — and where the third party held the data, the duty to notify landed on organisations with no facts to write
A prior weekly recorded European government's own operating infrastructure being compromised directly. This week the shape is different and, for planning purposes, harder: in all six of the week's European public-sector and critical-infrastructure disclosures a third party stood somewhere on the line — supplying the credentials the intruder used, holding the data that was taken, or owning the security work that was not done. In two of them that separation ran all the way to the notification, so the organisation that knows what happened and the organisation that owes an answer are not the same body.
Poland supplies the extreme case. MyDr, one of the country's largest electronic medical record providers, confirmed on 12 August that it was the target of a deliberate external criminal act, said the data is likely historical, and stated it cannot yet say what was taken (MyDr, 2026-08-12). The following day the theft was reported at almost 19 million patients' data, with Poland's digital affairs minister Krzysztof Gawkowski quoted calling it one of the largest incidents in the country's history (Notes from Poland, 2026-08-13); Gazeta Prawna puts the stolen database at over 2 TB (Gazeta Prawna, 2026-08-13), and the data-protection authority UODO stated that the obligation to notify affected individuals rests with the healthcare controllers that used MyDr's services (Gazeta Prawna, 2026-08-13) — around 12,000 medical facilities (Notes from Poland, 2026-08-13). That is not a technicality. It means the single organisation that knows what happened has no duty to tell anyone, and the twelve thousand organisations that have the duty know only what they read in the press. The same structure produced a smaller, cleaner illustration in the Netherlands: one intrusion at CEVA Logistics, the contract-logistics arm of CMA CGM, generated breach reports to the Dutch data-protection authority from ten separate organisations, because CEVA processes fulfilment data on behalf of unrelated clients (TechCrunch, 2026-08-10); bol.com, one of them, told its own partners that two order-processing systems at one fulfilment centre were involved and that customer data may have been viewed or copied (bol.com, 2026-08-06).
Where the third party is on the access path rather than the data path, the same asymmetry shows up as a detection problem. France's Direction générale des Finances publiques confirmed that intrusions in June and July used the stolen credentials of a DGFiP agent and of an authorised third party, and were used to view and extract data on 678,000 individuals and businesses (Ministère de l'Économie et des Finances, 2026-08-14). Żabka's confirmed intrusion reached its ticketing system through an external service provider's account (Niebezpiecznik, 2026-08-03). Retelit, one of Italy's largest business telecommunications and cloud operators, was compromised on 8 June in an extortion attack claimed by Qilin, and made no announcement through its own channels — the confirmation came as a right-of-reply after IrpiMedia published, scoping the damage to virtualisation infrastructure in three of its 38 data centres, one of them the site certified for Retelit's own backup and service continuity (IrpiMedia, 2026-08-04). Retelit serves 193 public administrations; those customers learned about a two-month-old intrusion from a newspaper.
The week's regulator supplied the governance version of the same gap, and it is the most directly usable finding here. The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office on 12 August after an intruder held access to its public website and content management system from August 2022 to March 2023 and staged the data of up to 10,920 people for theft. The ICO's stated cause is not a technology failure: ACRO had contracted patch management to third parties without establishing who internally was responsible for identifying and monitoring critical updates, and did not adequately investigate security alerts that would have surfaced the intrusion earlier. The ICO also names network segmentation among the mitigating factors it weighed, because it kept the attacker out of core systems (UK Information Commissioner's Office, 2026-08-12).
Triage: third-party account misuse is hard to separate from third-party account use, and the discriminators are contextual rather than atomic. A supplier or contractor account is defined by a narrow, repetitive and scheduled access pattern — a fixed set of systems, a working-hours profile matching the supplier's own jurisdiction, a stable set of source addresses belonging to the supplier's estate. The signals worth alerting on are deviations from that shape rather than the access itself: authentication from a network range with no prior relationship to that supplier, access to systems outside the contracted scope, use of the platform's own bulk export or reporting functions by an account that has never used them before, and activity continuing outside the contract's active periods. The DGFiP case adds the timing discriminator that matters most for scoping: the account was cut when the intrusion was detected, and the theft had already happened — so the review that establishes impact has to reconstruct what the account reached before containment, not merely confirm it stopped afterwards.
ATT&CK mapping
6 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
T1199Trusted Relationship
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Privilege Escalation TA0004
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
T1078.004Valid Accounts: Cloud Accounts
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Collection TA0009
T1005Data from Local System
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
T1213Data from Information Repositories
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.