BlackTree Security · Infrastructure · Automation · AI

The Classified Network Held. The Mobile Layer Still Mapped Belgium’s Intelligence Service.

Belgium’s civilian intelligence service kept its classified internal network beyond the attackers’ reach. The mobile-management layer still exposed a map of the people around it.

Reporting published in June says an unknown threat actor compromised the State Security Service, commonly known as the VSSE, through Ivanti Endpoint Manager Mobile. The service used EPMM to manage work phones and their access rights.

The intrusion reportedly lasted from May 2025 until spring 2026. Potentially exposed data included names, phone numbers, email addresses, device identifiers, GPS positions and details of people contacted through the phones.

That is not the same as access to classified intelligence. Available reporting says the attackers did not enter the internal network that carries confidential and secret information. It is still an operational-security incident with consequences that ordinary breach language understates.

The phone directory was an intelligence product

A contact list from an intelligence service is not merely a collection of personal records. Names, numbers, locations and communication relationships can reveal staffing patterns, office structures, working hours, travel, trusted external contacts and unusual bursts of activity.

Even incomplete data can support targeting. It can make a phishing message more credible, identify a person’s professional circle or expose a relationship that should not be publicly visible. Repeated GPS observations can turn a managed phone into a pattern-of-life sensor.

The distinction matters because a breach assessment based only on whether classified files were stolen can miss the new capability gained by the attacker. The exposed mobile layer may help an adversary decide whom to approach, impersonate, surveil or pressure next.

The security boundary moved into mobile management

EPMM is designed to enforce policy on devices, applications and access. That makes it a concentration point for trust. It can know which device belongs to which person, which services the device may reach and how the organisation expects the phone to identify itself.

Belgium’s Centre for Cybersecurity separately warned in May that Ivanti had observed limited exploitation of an authenticated EPMM remote-code-execution flaw. Ivanti believed the administrative credentials used in those cases came from earlier exploitation of a January vulnerability. The public reporting about the VSSE incident does not identify the exact vulnerability or prove that this was the same chain.

That evidentiary limit is important. The incident should not be assigned to a specific CVE, actor or campaign without stronger confirmation. What can be said is that an endpoint-management system created a route to high-value identity and device data even while the most sensitive network remained segmented.

Recovery has to include the people and their relationships

Patching the server closes a software path. It does not erase data already collected or restore the secrecy of a contact graph. A useful response therefore has to extend beyond rebuilding the EPMM appliance.

  • Identify which employee and contact records were reachable during the full exposure period.
  • Rotate administrative and device-management credentials from a trusted environment.
  • Reissue certificates or device identities where the integrity of enrolment cannot be established.
  • Review unusual device enrolment, Sentry registration, administrative actions and policy changes.
  • Brief affected staff and external contacts on plausible impersonation and social-engineering scenarios.
  • Treat exposed location and relationship data as an ongoing counter-intelligence risk, not a closed privacy notification.

The incident also argues for separating mobile-management telemetry from identity data wherever the product and operational model allow it. A platform may need authority over a device without retaining every relationship that makes the user intelligible to an attacker.

The classified network appears to have held. The surrounding trust layer did not. For an intelligence service, the metadata around a secret can be almost as useful as the secret itself.

Update, 1 September 2026: three exploited EPMM flaws sharpen the exposure

Public reporting still does not establish which vulnerability was used against Belgium’s VSSE. That attribution limit remains important. Separate vendor and government records do, however, identify three exploited EPMM code-execution paths that belong in the risk context.

  • CVE-2026-1281 and CVE-2026-1340 are critical code-injection flaws that can allow unauthenticated remote code execution. Ivanti supplied branch-specific RPM fixes.
  • CVE-2026-6973 is an authenticated remote-code-execution flaw. It requires an EPMM administrator account and is fixed in 12.8.0.1, 12.7.0.1 and 12.6.1.1.

CISA lists all three as known exploited. None of that proves that any one of them caused the VSSE breach. It does show why an internet-reachable mobile-management server must be treated as a control plane with access to identities, devices, location data and trusted communications.

Primary sources: Ivanti advisory for CVE-2026-1281 and CVE-2026-1340, Ivanti May EPMM advisory, Unit 42 analysis and the CISA KEV catalogue.

Sources: CERT-EU Cyber Brief 26-07 (published in July 2026; the source page provides no publication time), Techzine: Belgian State Security hit by Ivanti data breach (published 22 June 2026 at 09:59 CEST), Centre for Cybersecurity Belgium EPMM advisory (published 7 May 2026; no publication time provided, updated 7 June 2026), and NCSC-NL advisory NCSC-2026-0135 (published 7 May 2026 at 18:17 Europe/Amsterdam).

Leave a Reply

Your email address will not be published. Required fields are marked *