Five European public bodies disclosed breaches this week and not one of them could say what had happened — and in three of the five it was the attacker, not a control, that decided when the disclosure was made
A prior weekly recorded six European disclosures in which a third party sat on the access path or held the data, displacing the duty to notify onto organisations with no facts to write. This week's five are the same problem seen from inside the disclosing organisation, and the third party is not always the reason: in each case a public body published a notification whose central question — who was affected, and how — it could not answer, and in three of the five the timing of the disclosure was set by the attacker rather than by the victim's own detection.
Where the evidence was destroyed. The Upper Austrian Chamber of Labour disclosed on 2026-08-16 that unknown perpetrators had reached parts of its IT systems on 2026-08-10 and obtained access to data, and states that the extent "kann aufgrund gezielter Spurenverwischung durch die Täter derzeit nicht festgestellt werden" — cannot currently be established because of deliberate trace removal by the perpetrators — "auch nicht, ob und welche personenbezogenen Mitgliederdaten konkret betroffen sind", nor whether and which members' personal data were specifically affected (Arbeiterkammer Oberösterreich, 2026-08-16). The anti-forensic work did not hide the intrusion — that was detected. It removed the ability to bound it, which converts a scoped notification into a blanket one: every member now receives an individual letter by post under Article 34 GDPR, and the chamber has had to warn its entire membership to expect fraudulent messages purporting to come from it.
Where the monitoring that was bought was not the monitoring that noticed. Latvia's Road Traffic Safety Directorate states that between 8 and 10 August an attacker obtained payment-receipt data going back to 2008 on 1.2 million individuals and 200,000 legal entities — names, personal identity codes, payment amounts and dates, licence plates and registered addresses (CERT.LV, 2026-08-18). CSDD's own employees found and stopped the intrusion within several hours, while its outsourced IT provider neither detected it nor alerted the agency (inbox.eu, 2026-08-19). The provider's first public comment is where the gap becomes legible: it says it is too early to draw conclusions about causes, that its contractual responsibility extends only to certain parts of CSDD's IT infrastructure rather than the agency's whole network, has not disclosed how that scope was drawn, and confirms it engaged two subcontractors to fulfil the contract (inbox.eu, 2026-08-19). Nobody disputes that monitoring was contracted. What nobody had established, before it mattered, was the boundary of what "monitored" covered — and that boundary is now being drawn retrospectively by one of the two parties.
Where the attacker rang the bell. Three of the five disclosures happened when they did because the attacker acted, not because a control fired. At Martigny-Combe in Valais, the commune's external IT-security contractor traced the compromise of the municipal secretariat's mailbox back to 10 August, when an employee opened a malicious email without realising it; nothing surfaced until 18 August, when the attacker used that trusted communal mailbox to send a fraudulent message to roughly 450 of the commune's own correspondents, and it is that send which caused the commune to notice (Le Nouvelliste, 2026-08-20); the commune's own communiqué gives 18 August as the detection date (Commune de Martigny-Combe, 2026-08-20). HWZ Hochschule für Wirtschaft Zürich told students and alumni that their names, addresses, phone numbers, student-administration records, bank details and sick-leave notifications had been taken, and that the attack came through an external IT service provider's infrastructure rather than the school's own local systems (Inside Paradeplatz, 2026-08-22) — two days after an extortion group's leak-site listing of a Swiss data-centre operator named the school's domain among eight. And the regional government of Castilla-La Mancha confirmed a cyberattack, that response protocols were activated and that potentially affected individuals had been informed, while confirming nothing about volume, data categories or access route; everything circulating about what was taken — student and family records, files on pupils with specific educational-support needs, school-census and electoral material — is the extortion group's claim, which the reporting outlet states plainly must be treated as unverified (Escudo Digital, 2026-08-18).
Triage: the discriminator common to the whole set is a negative one, and it is worth building alerts on because it is the shape all five share — evidence that stops arriving. A log source that goes quiet while its host stays up, an event-log sequence with a hole in it, an audit or logging service stopped outside a change window, or a forwarder whose volume drops sharply against its own baseline. Routine rotation and maintenance produce similar gaps, so the separators are that maintenance is scheduled, is performed by accounts that do it regularly, and leaves the host's other telemetry intact. Where a supplier holds the data rather than the logs, the equivalent control is not technical at all: a current inventory of what each provider processes, and a contractual notification window short enough that the leak site is not how you find out.
ATT&CK mapping
4 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1199Trusted Relationship
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Stealth TA0005
T1070Indicator Removal
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Collection TA0009
T1114Email Collection
Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.
Impact TA0040
T1657Financial Theft
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.